Account for missing balance in splice max commitment output tracking - #4417

Merged
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output
Feb 20, 2026
Merged

Account for missing balance in splice max commitment output tracking#4417
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

When a splice creates new funding, the monotonicity debug assertion trackers were initialized to the raw post-splice balance without accounting for pending HTLCs or anchor costs. Since splices can have in-flight HTLCs (unlike fresh channel opens), the first commitment transaction's actual balance was lower than the initialized max, causing the debug assertion in ChannelContext::build_commitment_transaction to fire.

@wpaulinowpaulino added this to the 0.3 milestone Feb 13, 2026
@wpaulinowpaulino self-assigned this Feb 13, 2026
@ldk-reviews-bot

ldk-reviews-bot commented Feb 13, 2026

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Feb 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.91%. Comparing base (153e57e) to head (034892b).
⚠️ Report is 20 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #4417 +/- ##
=======================================
Coverage 85.90% 85.91% =======================================
Files 156 156 Lines 103965 103975 +10 Branches 103965 103975 +10 =======================================
+ Hits 89316 89332 +16 + Misses 12128 12119 -9 - Partials 2521 2524 +3 
FlagCoverage Δ
tests85.91% <100.00%> (+<0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the direction I have in mind what do you think ? We'd also assert that a balance that is under the new reserve did not decrease across the splice. Probably want to rename the state variables to highlight that once we are above the reserve, these track the balance on the previous commitment.

diff --git a/lightning/src/ln/channel.rs b/lightning/src/ln/channel.rs
index b8dc90ef9..8de424beb 100644
--- a/lightning/src/ln/channel.rs+++ b/lightning/src/ln/channel.rs@@ -2772,55 +2772,18 @@ impl FundingScope {
context.counterparty_dust_limit_satoshis,
);
- // Account for in-flight HTLCs and anchor outputs when initializing the max- // commitment tx output trackers. Unlike a fresh channel open (which has no HTLCs),- // a splice may have pending HTLCs whose amounts are subtracted from the balances- // in the commitment transaction. Without this adjustment, the monotonicity debug- // assertion in `build_commitment_transaction` would fire on the first commitment.- #[cfg(debug_assertions)]- let (local_balance_msat, remote_balance_msat) = {- let pending_outbound_htlcs_value_msat: u64 =- context.pending_outbound_htlcs.iter().map(|h| h.amount_msat).sum();- let pending_inbound_htlcs_value_msat: u64 =- context.pending_inbound_htlcs.iter().map(|h| h.amount_msat).sum();- let channel_type = &post_channel_transaction_parameters.channel_type_features;- let total_anchors_sat = if channel_type.supports_anchors_zero_fee_htlc_tx() {- ANCHOR_OUTPUT_VALUE_SATOSHI * 2- } else {- 0- };- let post_value_to_remote_msat =- (post_channel_value * 1000).saturating_sub(post_value_to_self_msat);- if post_channel_transaction_parameters.is_outbound_from_holder {- (- post_value_to_self_msat- .saturating_sub(pending_outbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- post_value_to_remote_msat.saturating_sub(pending_inbound_htlcs_value_msat),- )- } else {- (- post_value_to_self_msat.saturating_sub(pending_outbound_htlcs_value_msat),- post_value_to_remote_msat- .saturating_sub(pending_inbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- )- }- };-
Self {
channel_transaction_parameters: post_channel_transaction_parameters,
value_to_self_msat: post_value_to_self_msat,
funding_transaction: None,
counterparty_selected_channel_reserve_satoshis,
holder_selected_channel_reserve_satoshis,
+ // Here we copy over these values; if the party is below the reserve under the new funding+ // scope, their balance MUST NOT decrease.
#[cfg(debug_assertions)]
- holder_max_commitment_tx_output: Mutex::new((local_balance_msat, remote_balance_msat)),+ holder_max_commitment_tx_output: Mutex::new(prev_funding.holder_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(debug_assertions)]
- counterparty_max_commitment_tx_output: Mutex::new((- local_balance_msat,- remote_balance_msat,- )),+ counterparty_max_commitment_tx_output: Mutex::new(prev_funding.counterparty_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(any(test, fuzzing))]
next_local_fee: Mutex::new(PredictedNextFee::default()),
#[cfg(any(test, fuzzing))]
@@ -5544,12 +5507,21 @@ impl<SP: SignerProvider> ChannelContext<SP> {
} else {
funding.counterparty_max_commitment_tx_output.lock().unwrap()
};
- debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat || stats.local_balance_before_fee_msat / 1000 >= funding.counterparty_selected_channel_reserve_satoshis.unwrap());- broadcaster_max_commitment_tx_output.0 = cmp::max(broadcaster_max_commitment_tx_output.0, stats.local_balance_before_fee_msat);- debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat || stats.remote_balance_before_fee_msat / 1000 >= funding.holder_selected_channel_reserve_satoshis);- broadcaster_max_commitment_tx_output.1 = cmp::max(broadcaster_max_commitment_tx_output.1, stats.remote_balance_before_fee_msat);- }+ if stats.local_balance_before_fee_msat / 1000 < funding.counterparty_selected_channel_reserve_satoshis.unwrap() {+ // If local is below the reserve on this new commitment, local balance MUST be greater than+ // or equal to local balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.0 = stats.local_balance_before_fee_msat;++ if stats.remote_balance_before_fee_msat / 1000 < funding.holder_selected_channel_reserve_satoshis {+ // If remote is below the reserve on this new commitment, remote balance MUST be greater than+ // or equal to remote balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.1 = stats.remote_balance_before_fee_msat;+ }
// This populates the HTLC-source table with the indices from the HTLCs in the commitment
// transaction.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 27bf59a to 44b59ceCompareFebruary 17, 2026 17:33
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
wpaulinoand others added 2 commits February 18, 2026 16:23
When we create the post-splice `FundingScope`, the monotonicity debug
assertion trackers were initialized to the post-splice balance without
accounting for pending HTLCs or anchor costs. Since splices can have
in-flight HTLCs (unlike fresh channel opens), the first commitment
transaction's actual balance was lower than the initialized max, causing
the debug assertion in `ChannelContext::build_commitment_transaction` to
fire.
Note that we don't need to recompute the full post-splice balance here.
We can rely on the pre-splice `FundingScope`'s
`holder/counterparty_max_commitment_tx_output` instead since they're
already accounted for there.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
These assertions made sure that our balance would never dip below the
reserve, and if they ever were, that the balance must only move towards
meeting the reserve. With splicing, this doesn't always work, as a node
that is not interested in contributing could end up below the reserve of
the post-splice channel. Therefore, we rework these assertions such that
we only keep track of the previous commitment transaction balance, and
compare against the current, ensuring that our balance only increases
when below the reserve.
@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 44b59ce to 034892bCompareFebruary 19, 2026 00:23

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks

@tankyleo
tankyleo merged commit 62c7575 into lightningdevkit:mainFeb 20, 2026
21 of 22 checks passed
@wpaulino
wpaulino deleted the fix-splice-funding-scope-max-commitment-output branch February 20, 2026 17:57
@jkczyzjkczyz mentioned this pull request Mar 19, 2026
50 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@tankyleo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Account for missing balance in splice max commitment output tracking - #4417

Merged
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output
Feb 20, 2026
Merged

Account for missing balance in splice max commitment output tracking#4417
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

When a splice creates new funding, the monotonicity debug assertion trackers were initialized to the raw post-splice balance without accounting for pending HTLCs or anchor costs. Since splices can have in-flight HTLCs (unlike fresh channel opens), the first commitment transaction's actual balance was lower than the initialized max, causing the debug assertion in ChannelContext::build_commitment_transaction to fire.

@wpaulinowpaulino added this to the 0.3 milestone Feb 13, 2026
@wpaulinowpaulino self-assigned this Feb 13, 2026
@ldk-reviews-bot

ldk-reviews-bot commented Feb 13, 2026

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Feb 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.91%. Comparing base (153e57e) to head (034892b).
⚠️ Report is 20 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #4417 +/- ##
=======================================
Coverage 85.90% 85.91% =======================================
Files 156 156 Lines 103965 103975 +10 Branches 103965 103975 +10 =======================================
+ Hits 89316 89332 +16 + Misses 12128 12119 -9 - Partials 2521 2524 +3 
FlagCoverage Δ
tests85.91% <100.00%> (+<0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the direction I have in mind what do you think ? We'd also assert that a balance that is under the new reserve did not decrease across the splice. Probably want to rename the state variables to highlight that once we are above the reserve, these track the balance on the previous commitment.

diff --git a/lightning/src/ln/channel.rs b/lightning/src/ln/channel.rs
index b8dc90ef9..8de424beb 100644
--- a/lightning/src/ln/channel.rs+++ b/lightning/src/ln/channel.rs@@ -2772,55 +2772,18 @@ impl FundingScope {
context.counterparty_dust_limit_satoshis,
);
- // Account for in-flight HTLCs and anchor outputs when initializing the max- // commitment tx output trackers. Unlike a fresh channel open (which has no HTLCs),- // a splice may have pending HTLCs whose amounts are subtracted from the balances- // in the commitment transaction. Without this adjustment, the monotonicity debug- // assertion in `build_commitment_transaction` would fire on the first commitment.- #[cfg(debug_assertions)]- let (local_balance_msat, remote_balance_msat) = {- let pending_outbound_htlcs_value_msat: u64 =- context.pending_outbound_htlcs.iter().map(|h| h.amount_msat).sum();- let pending_inbound_htlcs_value_msat: u64 =- context.pending_inbound_htlcs.iter().map(|h| h.amount_msat).sum();- let channel_type = &post_channel_transaction_parameters.channel_type_features;- let total_anchors_sat = if channel_type.supports_anchors_zero_fee_htlc_tx() {- ANCHOR_OUTPUT_VALUE_SATOSHI * 2- } else {- 0- };- let post_value_to_remote_msat =- (post_channel_value * 1000).saturating_sub(post_value_to_self_msat);- if post_channel_transaction_parameters.is_outbound_from_holder {- (- post_value_to_self_msat- .saturating_sub(pending_outbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- post_value_to_remote_msat.saturating_sub(pending_inbound_htlcs_value_msat),- )- } else {- (- post_value_to_self_msat.saturating_sub(pending_outbound_htlcs_value_msat),- post_value_to_remote_msat- .saturating_sub(pending_inbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- )- }- };-
Self {
channel_transaction_parameters: post_channel_transaction_parameters,
value_to_self_msat: post_value_to_self_msat,
funding_transaction: None,
counterparty_selected_channel_reserve_satoshis,
holder_selected_channel_reserve_satoshis,
+ // Here we copy over these values; if the party is below the reserve under the new funding+ // scope, their balance MUST NOT decrease.
#[cfg(debug_assertions)]
- holder_max_commitment_tx_output: Mutex::new((local_balance_msat, remote_balance_msat)),+ holder_max_commitment_tx_output: Mutex::new(prev_funding.holder_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(debug_assertions)]
- counterparty_max_commitment_tx_output: Mutex::new((- local_balance_msat,- remote_balance_msat,- )),+ counterparty_max_commitment_tx_output: Mutex::new(prev_funding.counterparty_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(any(test, fuzzing))]
next_local_fee: Mutex::new(PredictedNextFee::default()),
#[cfg(any(test, fuzzing))]
@@ -5544,12 +5507,21 @@ impl<SP: SignerProvider> ChannelContext<SP> {
} else {
funding.counterparty_max_commitment_tx_output.lock().unwrap()
};
- debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat || stats.local_balance_before_fee_msat / 1000 >= funding.counterparty_selected_channel_reserve_satoshis.unwrap());- broadcaster_max_commitment_tx_output.0 = cmp::max(broadcaster_max_commitment_tx_output.0, stats.local_balance_before_fee_msat);- debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat || stats.remote_balance_before_fee_msat / 1000 >= funding.holder_selected_channel_reserve_satoshis);- broadcaster_max_commitment_tx_output.1 = cmp::max(broadcaster_max_commitment_tx_output.1, stats.remote_balance_before_fee_msat);- }+ if stats.local_balance_before_fee_msat / 1000 < funding.counterparty_selected_channel_reserve_satoshis.unwrap() {+ // If local is below the reserve on this new commitment, local balance MUST be greater than+ // or equal to local balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.0 = stats.local_balance_before_fee_msat;++ if stats.remote_balance_before_fee_msat / 1000 < funding.holder_selected_channel_reserve_satoshis {+ // If remote is below the reserve on this new commitment, remote balance MUST be greater than+ // or equal to remote balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.1 = stats.remote_balance_before_fee_msat;+ }
// This populates the HTLC-source table with the indices from the HTLCs in the commitment
// transaction.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 27bf59a to 44b59ceCompareFebruary 17, 2026 17:33
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
wpaulinoand others added 2 commits February 18, 2026 16:23
When we create the post-splice `FundingScope`, the monotonicity debug
assertion trackers were initialized to the post-splice balance without
accounting for pending HTLCs or anchor costs. Since splices can have
in-flight HTLCs (unlike fresh channel opens), the first commitment
transaction's actual balance was lower than the initialized max, causing
the debug assertion in `ChannelContext::build_commitment_transaction` to
fire.
Note that we don't need to recompute the full post-splice balance here.
We can rely on the pre-splice `FundingScope`'s
`holder/counterparty_max_commitment_tx_output` instead since they're
already accounted for there.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
These assertions made sure that our balance would never dip below the
reserve, and if they ever were, that the balance must only move towards
meeting the reserve. With splicing, this doesn't always work, as a node
that is not interested in contributing could end up below the reserve of
the post-splice channel. Therefore, we rework these assertions such that
we only keep track of the previous commitment transaction balance, and
compare against the current, ensuring that our balance only increases
when below the reserve.
@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 44b59ce to 034892bCompareFebruary 19, 2026 00:23

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks

@tankyleo
tankyleo merged commit 62c7575 into lightningdevkit:mainFeb 20, 2026
21 of 22 checks passed
@wpaulino
wpaulino deleted the fix-splice-funding-scope-max-commitment-output branch February 20, 2026 17:57
@jkczyzjkczyz mentioned this pull request Mar 19, 2026
50 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@tankyleo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Account for missing balance in splice max commitment output tracking - #4417

Merged
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output
Feb 20, 2026
Merged

Account for missing balance in splice max commitment output tracking#4417
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

When a splice creates new funding, the monotonicity debug assertion trackers were initialized to the raw post-splice balance without accounting for pending HTLCs or anchor costs. Since splices can have in-flight HTLCs (unlike fresh channel opens), the first commitment transaction's actual balance was lower than the initialized max, causing the debug assertion in ChannelContext::build_commitment_transaction to fire.

@wpaulinowpaulino added this to the 0.3 milestone Feb 13, 2026
@wpaulinowpaulino self-assigned this Feb 13, 2026
@ldk-reviews-bot

ldk-reviews-bot commented Feb 13, 2026

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Feb 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.91%. Comparing base (153e57e) to head (034892b).
⚠️ Report is 20 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #4417 +/- ##
=======================================
Coverage 85.90% 85.91% =======================================
Files 156 156 Lines 103965 103975 +10 Branches 103965 103975 +10 =======================================
+ Hits 89316 89332 +16 + Misses 12128 12119 -9 - Partials 2521 2524 +3 
FlagCoverage Δ
tests85.91% <100.00%> (+<0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the direction I have in mind what do you think ? We'd also assert that a balance that is under the new reserve did not decrease across the splice. Probably want to rename the state variables to highlight that once we are above the reserve, these track the balance on the previous commitment.

diff --git a/lightning/src/ln/channel.rs b/lightning/src/ln/channel.rs
index b8dc90ef9..8de424beb 100644
--- a/lightning/src/ln/channel.rs+++ b/lightning/src/ln/channel.rs@@ -2772,55 +2772,18 @@ impl FundingScope {
context.counterparty_dust_limit_satoshis,
);
- // Account for in-flight HTLCs and anchor outputs when initializing the max- // commitment tx output trackers. Unlike a fresh channel open (which has no HTLCs),- // a splice may have pending HTLCs whose amounts are subtracted from the balances- // in the commitment transaction. Without this adjustment, the monotonicity debug- // assertion in `build_commitment_transaction` would fire on the first commitment.- #[cfg(debug_assertions)]- let (local_balance_msat, remote_balance_msat) = {- let pending_outbound_htlcs_value_msat: u64 =- context.pending_outbound_htlcs.iter().map(|h| h.amount_msat).sum();- let pending_inbound_htlcs_value_msat: u64 =- context.pending_inbound_htlcs.iter().map(|h| h.amount_msat).sum();- let channel_type = &post_channel_transaction_parameters.channel_type_features;- let total_anchors_sat = if channel_type.supports_anchors_zero_fee_htlc_tx() {- ANCHOR_OUTPUT_VALUE_SATOSHI * 2- } else {- 0- };- let post_value_to_remote_msat =- (post_channel_value * 1000).saturating_sub(post_value_to_self_msat);- if post_channel_transaction_parameters.is_outbound_from_holder {- (- post_value_to_self_msat- .saturating_sub(pending_outbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- post_value_to_remote_msat.saturating_sub(pending_inbound_htlcs_value_msat),- )- } else {- (- post_value_to_self_msat.saturating_sub(pending_outbound_htlcs_value_msat),- post_value_to_remote_msat- .saturating_sub(pending_inbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- )- }- };-
Self {
channel_transaction_parameters: post_channel_transaction_parameters,
value_to_self_msat: post_value_to_self_msat,
funding_transaction: None,
counterparty_selected_channel_reserve_satoshis,
holder_selected_channel_reserve_satoshis,
+ // Here we copy over these values; if the party is below the reserve under the new funding+ // scope, their balance MUST NOT decrease.
#[cfg(debug_assertions)]
- holder_max_commitment_tx_output: Mutex::new((local_balance_msat, remote_balance_msat)),+ holder_max_commitment_tx_output: Mutex::new(prev_funding.holder_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(debug_assertions)]
- counterparty_max_commitment_tx_output: Mutex::new((- local_balance_msat,- remote_balance_msat,- )),+ counterparty_max_commitment_tx_output: Mutex::new(prev_funding.counterparty_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(any(test, fuzzing))]
next_local_fee: Mutex::new(PredictedNextFee::default()),
#[cfg(any(test, fuzzing))]
@@ -5544,12 +5507,21 @@ impl<SP: SignerProvider> ChannelContext<SP> {
} else {
funding.counterparty_max_commitment_tx_output.lock().unwrap()
};
- debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat || stats.local_balance_before_fee_msat / 1000 >= funding.counterparty_selected_channel_reserve_satoshis.unwrap());- broadcaster_max_commitment_tx_output.0 = cmp::max(broadcaster_max_commitment_tx_output.0, stats.local_balance_before_fee_msat);- debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat || stats.remote_balance_before_fee_msat / 1000 >= funding.holder_selected_channel_reserve_satoshis);- broadcaster_max_commitment_tx_output.1 = cmp::max(broadcaster_max_commitment_tx_output.1, stats.remote_balance_before_fee_msat);- }+ if stats.local_balance_before_fee_msat / 1000 < funding.counterparty_selected_channel_reserve_satoshis.unwrap() {+ // If local is below the reserve on this new commitment, local balance MUST be greater than+ // or equal to local balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.0 = stats.local_balance_before_fee_msat;++ if stats.remote_balance_before_fee_msat / 1000 < funding.holder_selected_channel_reserve_satoshis {+ // If remote is below the reserve on this new commitment, remote balance MUST be greater than+ // or equal to remote balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.1 = stats.remote_balance_before_fee_msat;+ }
// This populates the HTLC-source table with the indices from the HTLCs in the commitment
// transaction.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 27bf59a to 44b59ceCompareFebruary 17, 2026 17:33
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
wpaulinoand others added 2 commits February 18, 2026 16:23
When we create the post-splice `FundingScope`, the monotonicity debug
assertion trackers were initialized to the post-splice balance without
accounting for pending HTLCs or anchor costs. Since splices can have
in-flight HTLCs (unlike fresh channel opens), the first commitment
transaction's actual balance was lower than the initialized max, causing
the debug assertion in `ChannelContext::build_commitment_transaction` to
fire.
Note that we don't need to recompute the full post-splice balance here.
We can rely on the pre-splice `FundingScope`'s
`holder/counterparty_max_commitment_tx_output` instead since they're
already accounted for there.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
These assertions made sure that our balance would never dip below the
reserve, and if they ever were, that the balance must only move towards
meeting the reserve. With splicing, this doesn't always work, as a node
that is not interested in contributing could end up below the reserve of
the post-splice channel. Therefore, we rework these assertions such that
we only keep track of the previous commitment transaction balance, and
compare against the current, ensuring that our balance only increases
when below the reserve.
@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 44b59ce to 034892bCompareFebruary 19, 2026 00:23

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks

@tankyleo
tankyleo merged commit 62c7575 into lightningdevkit:mainFeb 20, 2026
21 of 22 checks passed
@wpaulino
wpaulino deleted the fix-splice-funding-scope-max-commitment-output branch February 20, 2026 17:57
@jkczyzjkczyz mentioned this pull request Mar 19, 2026
50 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@tankyleo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Account for missing balance in splice max commitment output tracking - #4417

Merged
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output
Feb 20, 2026
Merged

Account for missing balance in splice max commitment output tracking#4417
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

When a splice creates new funding, the monotonicity debug assertion trackers were initialized to the raw post-splice balance without accounting for pending HTLCs or anchor costs. Since splices can have in-flight HTLCs (unlike fresh channel opens), the first commitment transaction's actual balance was lower than the initialized max, causing the debug assertion in ChannelContext::build_commitment_transaction to fire.

@wpaulinowpaulino added this to the 0.3 milestone Feb 13, 2026
@wpaulinowpaulino self-assigned this Feb 13, 2026
@ldk-reviews-bot

ldk-reviews-bot commented Feb 13, 2026

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Feb 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.91%. Comparing base (153e57e) to head (034892b).
⚠️ Report is 20 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #4417 +/- ##
=======================================
Coverage 85.90% 85.91% =======================================
Files 156 156 Lines 103965 103975 +10 Branches 103965 103975 +10 =======================================
+ Hits 89316 89332 +16 + Misses 12128 12119 -9 - Partials 2521 2524 +3 
FlagCoverage Δ
tests85.91% <100.00%> (+<0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the direction I have in mind what do you think ? We'd also assert that a balance that is under the new reserve did not decrease across the splice. Probably want to rename the state variables to highlight that once we are above the reserve, these track the balance on the previous commitment.

diff --git a/lightning/src/ln/channel.rs b/lightning/src/ln/channel.rs
index b8dc90ef9..8de424beb 100644
--- a/lightning/src/ln/channel.rs+++ b/lightning/src/ln/channel.rs@@ -2772,55 +2772,18 @@ impl FundingScope {
context.counterparty_dust_limit_satoshis,
);
- // Account for in-flight HTLCs and anchor outputs when initializing the max- // commitment tx output trackers. Unlike a fresh channel open (which has no HTLCs),- // a splice may have pending HTLCs whose amounts are subtracted from the balances- // in the commitment transaction. Without this adjustment, the monotonicity debug- // assertion in `build_commitment_transaction` would fire on the first commitment.- #[cfg(debug_assertions)]- let (local_balance_msat, remote_balance_msat) = {- let pending_outbound_htlcs_value_msat: u64 =- context.pending_outbound_htlcs.iter().map(|h| h.amount_msat).sum();- let pending_inbound_htlcs_value_msat: u64 =- context.pending_inbound_htlcs.iter().map(|h| h.amount_msat).sum();- let channel_type = &post_channel_transaction_parameters.channel_type_features;- let total_anchors_sat = if channel_type.supports_anchors_zero_fee_htlc_tx() {- ANCHOR_OUTPUT_VALUE_SATOSHI * 2- } else {- 0- };- let post_value_to_remote_msat =- (post_channel_value * 1000).saturating_sub(post_value_to_self_msat);- if post_channel_transaction_parameters.is_outbound_from_holder {- (- post_value_to_self_msat- .saturating_sub(pending_outbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- post_value_to_remote_msat.saturating_sub(pending_inbound_htlcs_value_msat),- )- } else {- (- post_value_to_self_msat.saturating_sub(pending_outbound_htlcs_value_msat),- post_value_to_remote_msat- .saturating_sub(pending_inbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- )- }- };-
Self {
channel_transaction_parameters: post_channel_transaction_parameters,
value_to_self_msat: post_value_to_self_msat,
funding_transaction: None,
counterparty_selected_channel_reserve_satoshis,
holder_selected_channel_reserve_satoshis,
+ // Here we copy over these values; if the party is below the reserve under the new funding+ // scope, their balance MUST NOT decrease.
#[cfg(debug_assertions)]
- holder_max_commitment_tx_output: Mutex::new((local_balance_msat, remote_balance_msat)),+ holder_max_commitment_tx_output: Mutex::new(prev_funding.holder_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(debug_assertions)]
- counterparty_max_commitment_tx_output: Mutex::new((- local_balance_msat,- remote_balance_msat,- )),+ counterparty_max_commitment_tx_output: Mutex::new(prev_funding.counterparty_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(any(test, fuzzing))]
next_local_fee: Mutex::new(PredictedNextFee::default()),
#[cfg(any(test, fuzzing))]
@@ -5544,12 +5507,21 @@ impl<SP: SignerProvider> ChannelContext<SP> {
} else {
funding.counterparty_max_commitment_tx_output.lock().unwrap()
};
- debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat || stats.local_balance_before_fee_msat / 1000 >= funding.counterparty_selected_channel_reserve_satoshis.unwrap());- broadcaster_max_commitment_tx_output.0 = cmp::max(broadcaster_max_commitment_tx_output.0, stats.local_balance_before_fee_msat);- debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat || stats.remote_balance_before_fee_msat / 1000 >= funding.holder_selected_channel_reserve_satoshis);- broadcaster_max_commitment_tx_output.1 = cmp::max(broadcaster_max_commitment_tx_output.1, stats.remote_balance_before_fee_msat);- }+ if stats.local_balance_before_fee_msat / 1000 < funding.counterparty_selected_channel_reserve_satoshis.unwrap() {+ // If local is below the reserve on this new commitment, local balance MUST be greater than+ // or equal to local balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.0 = stats.local_balance_before_fee_msat;++ if stats.remote_balance_before_fee_msat / 1000 < funding.holder_selected_channel_reserve_satoshis {+ // If remote is below the reserve on this new commitment, remote balance MUST be greater than+ // or equal to remote balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.1 = stats.remote_balance_before_fee_msat;+ }
// This populates the HTLC-source table with the indices from the HTLCs in the commitment
// transaction.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 27bf59a to 44b59ceCompareFebruary 17, 2026 17:33
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
wpaulinoand others added 2 commits February 18, 2026 16:23
When we create the post-splice `FundingScope`, the monotonicity debug
assertion trackers were initialized to the post-splice balance without
accounting for pending HTLCs or anchor costs. Since splices can have
in-flight HTLCs (unlike fresh channel opens), the first commitment
transaction's actual balance was lower than the initialized max, causing
the debug assertion in `ChannelContext::build_commitment_transaction` to
fire.
Note that we don't need to recompute the full post-splice balance here.
We can rely on the pre-splice `FundingScope`'s
`holder/counterparty_max_commitment_tx_output` instead since they're
already accounted for there.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
These assertions made sure that our balance would never dip below the
reserve, and if they ever were, that the balance must only move towards
meeting the reserve. With splicing, this doesn't always work, as a node
that is not interested in contributing could end up below the reserve of
the post-splice channel. Therefore, we rework these assertions such that
we only keep track of the previous commitment transaction balance, and
compare against the current, ensuring that our balance only increases
when below the reserve.
@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 44b59ce to 034892bCompareFebruary 19, 2026 00:23

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks

@tankyleo
tankyleo merged commit 62c7575 into lightningdevkit:mainFeb 20, 2026
21 of 22 checks passed
@wpaulino
wpaulino deleted the fix-splice-funding-scope-max-commitment-output branch February 20, 2026 17:57
@jkczyzjkczyz mentioned this pull request Mar 19, 2026
50 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@tankyleo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Account for missing balance in splice max commitment output tracking - #4417

Merged
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output
Feb 20, 2026
Merged

Account for missing balance in splice max commitment output tracking#4417
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

When a splice creates new funding, the monotonicity debug assertion trackers were initialized to the raw post-splice balance without accounting for pending HTLCs or anchor costs. Since splices can have in-flight HTLCs (unlike fresh channel opens), the first commitment transaction's actual balance was lower than the initialized max, causing the debug assertion in ChannelContext::build_commitment_transaction to fire.

@wpaulinowpaulino added this to the 0.3 milestone Feb 13, 2026
@wpaulinowpaulino self-assigned this Feb 13, 2026
@ldk-reviews-bot

ldk-reviews-bot commented Feb 13, 2026

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Feb 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.91%. Comparing base (153e57e) to head (034892b).
⚠️ Report is 20 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #4417 +/- ##
=======================================
Coverage 85.90% 85.91% =======================================
Files 156 156 Lines 103965 103975 +10 Branches 103965 103975 +10 =======================================
+ Hits 89316 89332 +16 + Misses 12128 12119 -9 - Partials 2521 2524 +3 
FlagCoverage Δ
tests85.91% <100.00%> (+<0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the direction I have in mind what do you think ? We'd also assert that a balance that is under the new reserve did not decrease across the splice. Probably want to rename the state variables to highlight that once we are above the reserve, these track the balance on the previous commitment.

diff --git a/lightning/src/ln/channel.rs b/lightning/src/ln/channel.rs
index b8dc90ef9..8de424beb 100644
--- a/lightning/src/ln/channel.rs+++ b/lightning/src/ln/channel.rs@@ -2772,55 +2772,18 @@ impl FundingScope {
context.counterparty_dust_limit_satoshis,
);
- // Account for in-flight HTLCs and anchor outputs when initializing the max- // commitment tx output trackers. Unlike a fresh channel open (which has no HTLCs),- // a splice may have pending HTLCs whose amounts are subtracted from the balances- // in the commitment transaction. Without this adjustment, the monotonicity debug- // assertion in `build_commitment_transaction` would fire on the first commitment.- #[cfg(debug_assertions)]- let (local_balance_msat, remote_balance_msat) = {- let pending_outbound_htlcs_value_msat: u64 =- context.pending_outbound_htlcs.iter().map(|h| h.amount_msat).sum();- let pending_inbound_htlcs_value_msat: u64 =- context.pending_inbound_htlcs.iter().map(|h| h.amount_msat).sum();- let channel_type = &post_channel_transaction_parameters.channel_type_features;- let total_anchors_sat = if channel_type.supports_anchors_zero_fee_htlc_tx() {- ANCHOR_OUTPUT_VALUE_SATOSHI * 2- } else {- 0- };- let post_value_to_remote_msat =- (post_channel_value * 1000).saturating_sub(post_value_to_self_msat);- if post_channel_transaction_parameters.is_outbound_from_holder {- (- post_value_to_self_msat- .saturating_sub(pending_outbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- post_value_to_remote_msat.saturating_sub(pending_inbound_htlcs_value_msat),- )- } else {- (- post_value_to_self_msat.saturating_sub(pending_outbound_htlcs_value_msat),- post_value_to_remote_msat- .saturating_sub(pending_inbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- )- }- };-
Self {
channel_transaction_parameters: post_channel_transaction_parameters,
value_to_self_msat: post_value_to_self_msat,
funding_transaction: None,
counterparty_selected_channel_reserve_satoshis,
holder_selected_channel_reserve_satoshis,
+ // Here we copy over these values; if the party is below the reserve under the new funding+ // scope, their balance MUST NOT decrease.
#[cfg(debug_assertions)]
- holder_max_commitment_tx_output: Mutex::new((local_balance_msat, remote_balance_msat)),+ holder_max_commitment_tx_output: Mutex::new(prev_funding.holder_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(debug_assertions)]
- counterparty_max_commitment_tx_output: Mutex::new((- local_balance_msat,- remote_balance_msat,- )),+ counterparty_max_commitment_tx_output: Mutex::new(prev_funding.counterparty_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(any(test, fuzzing))]
next_local_fee: Mutex::new(PredictedNextFee::default()),
#[cfg(any(test, fuzzing))]
@@ -5544,12 +5507,21 @@ impl<SP: SignerProvider> ChannelContext<SP> {
} else {
funding.counterparty_max_commitment_tx_output.lock().unwrap()
};
- debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat || stats.local_balance_before_fee_msat / 1000 >= funding.counterparty_selected_channel_reserve_satoshis.unwrap());- broadcaster_max_commitment_tx_output.0 = cmp::max(broadcaster_max_commitment_tx_output.0, stats.local_balance_before_fee_msat);- debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat || stats.remote_balance_before_fee_msat / 1000 >= funding.holder_selected_channel_reserve_satoshis);- broadcaster_max_commitment_tx_output.1 = cmp::max(broadcaster_max_commitment_tx_output.1, stats.remote_balance_before_fee_msat);- }+ if stats.local_balance_before_fee_msat / 1000 < funding.counterparty_selected_channel_reserve_satoshis.unwrap() {+ // If local is below the reserve on this new commitment, local balance MUST be greater than+ // or equal to local balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.0 = stats.local_balance_before_fee_msat;++ if stats.remote_balance_before_fee_msat / 1000 < funding.holder_selected_channel_reserve_satoshis {+ // If remote is below the reserve on this new commitment, remote balance MUST be greater than+ // or equal to remote balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.1 = stats.remote_balance_before_fee_msat;+ }
// This populates the HTLC-source table with the indices from the HTLCs in the commitment
// transaction.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 27bf59a to 44b59ceCompareFebruary 17, 2026 17:33
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
wpaulinoand others added 2 commits February 18, 2026 16:23
When we create the post-splice `FundingScope`, the monotonicity debug
assertion trackers were initialized to the post-splice balance without
accounting for pending HTLCs or anchor costs. Since splices can have
in-flight HTLCs (unlike fresh channel opens), the first commitment
transaction's actual balance was lower than the initialized max, causing
the debug assertion in `ChannelContext::build_commitment_transaction` to
fire.
Note that we don't need to recompute the full post-splice balance here.
We can rely on the pre-splice `FundingScope`'s
`holder/counterparty_max_commitment_tx_output` instead since they're
already accounted for there.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
These assertions made sure that our balance would never dip below the
reserve, and if they ever were, that the balance must only move towards
meeting the reserve. With splicing, this doesn't always work, as a node
that is not interested in contributing could end up below the reserve of
the post-splice channel. Therefore, we rework these assertions such that
we only keep track of the previous commitment transaction balance, and
compare against the current, ensuring that our balance only increases
when below the reserve.
@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 44b59ce to 034892bCompareFebruary 19, 2026 00:23

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks

@tankyleo
tankyleo merged commit 62c7575 into lightningdevkit:mainFeb 20, 2026
21 of 22 checks passed
@wpaulino
wpaulino deleted the fix-splice-funding-scope-max-commitment-output branch February 20, 2026 17:57
@jkczyzjkczyz mentioned this pull request Mar 19, 2026
50 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@tankyleo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Account for missing balance in splice max commitment output tracking - #4417

Merged
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output
Feb 20, 2026
Merged

Account for missing balance in splice max commitment output tracking#4417
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

When a splice creates new funding, the monotonicity debug assertion trackers were initialized to the raw post-splice balance without accounting for pending HTLCs or anchor costs. Since splices can have in-flight HTLCs (unlike fresh channel opens), the first commitment transaction's actual balance was lower than the initialized max, causing the debug assertion in ChannelContext::build_commitment_transaction to fire.

@wpaulinowpaulino added this to the 0.3 milestone Feb 13, 2026
@wpaulinowpaulino self-assigned this Feb 13, 2026
@ldk-reviews-bot

ldk-reviews-bot commented Feb 13, 2026

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Feb 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.91%. Comparing base (153e57e) to head (034892b).
⚠️ Report is 20 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #4417 +/- ##
=======================================
Coverage 85.90% 85.91% =======================================
Files 156 156 Lines 103965 103975 +10 Branches 103965 103975 +10 =======================================
+ Hits 89316 89332 +16 + Misses 12128 12119 -9 - Partials 2521 2524 +3 
FlagCoverage Δ
tests85.91% <100.00%> (+<0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the direction I have in mind what do you think ? We'd also assert that a balance that is under the new reserve did not decrease across the splice. Probably want to rename the state variables to highlight that once we are above the reserve, these track the balance on the previous commitment.

diff --git a/lightning/src/ln/channel.rs b/lightning/src/ln/channel.rs
index b8dc90ef9..8de424beb 100644
--- a/lightning/src/ln/channel.rs+++ b/lightning/src/ln/channel.rs@@ -2772,55 +2772,18 @@ impl FundingScope {
context.counterparty_dust_limit_satoshis,
);
- // Account for in-flight HTLCs and anchor outputs when initializing the max- // commitment tx output trackers. Unlike a fresh channel open (which has no HTLCs),- // a splice may have pending HTLCs whose amounts are subtracted from the balances- // in the commitment transaction. Without this adjustment, the monotonicity debug- // assertion in `build_commitment_transaction` would fire on the first commitment.- #[cfg(debug_assertions)]- let (local_balance_msat, remote_balance_msat) = {- let pending_outbound_htlcs_value_msat: u64 =- context.pending_outbound_htlcs.iter().map(|h| h.amount_msat).sum();- let pending_inbound_htlcs_value_msat: u64 =- context.pending_inbound_htlcs.iter().map(|h| h.amount_msat).sum();- let channel_type = &post_channel_transaction_parameters.channel_type_features;- let total_anchors_sat = if channel_type.supports_anchors_zero_fee_htlc_tx() {- ANCHOR_OUTPUT_VALUE_SATOSHI * 2- } else {- 0- };- let post_value_to_remote_msat =- (post_channel_value * 1000).saturating_sub(post_value_to_self_msat);- if post_channel_transaction_parameters.is_outbound_from_holder {- (- post_value_to_self_msat- .saturating_sub(pending_outbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- post_value_to_remote_msat.saturating_sub(pending_inbound_htlcs_value_msat),- )- } else {- (- post_value_to_self_msat.saturating_sub(pending_outbound_htlcs_value_msat),- post_value_to_remote_msat- .saturating_sub(pending_inbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- )- }- };-
Self {
channel_transaction_parameters: post_channel_transaction_parameters,
value_to_self_msat: post_value_to_self_msat,
funding_transaction: None,
counterparty_selected_channel_reserve_satoshis,
holder_selected_channel_reserve_satoshis,
+ // Here we copy over these values; if the party is below the reserve under the new funding+ // scope, their balance MUST NOT decrease.
#[cfg(debug_assertions)]
- holder_max_commitment_tx_output: Mutex::new((local_balance_msat, remote_balance_msat)),+ holder_max_commitment_tx_output: Mutex::new(prev_funding.holder_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(debug_assertions)]
- counterparty_max_commitment_tx_output: Mutex::new((- local_balance_msat,- remote_balance_msat,- )),+ counterparty_max_commitment_tx_output: Mutex::new(prev_funding.counterparty_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(any(test, fuzzing))]
next_local_fee: Mutex::new(PredictedNextFee::default()),
#[cfg(any(test, fuzzing))]
@@ -5544,12 +5507,21 @@ impl<SP: SignerProvider> ChannelContext<SP> {
} else {
funding.counterparty_max_commitment_tx_output.lock().unwrap()
};
- debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat || stats.local_balance_before_fee_msat / 1000 >= funding.counterparty_selected_channel_reserve_satoshis.unwrap());- broadcaster_max_commitment_tx_output.0 = cmp::max(broadcaster_max_commitment_tx_output.0, stats.local_balance_before_fee_msat);- debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat || stats.remote_balance_before_fee_msat / 1000 >= funding.holder_selected_channel_reserve_satoshis);- broadcaster_max_commitment_tx_output.1 = cmp::max(broadcaster_max_commitment_tx_output.1, stats.remote_balance_before_fee_msat);- }+ if stats.local_balance_before_fee_msat / 1000 < funding.counterparty_selected_channel_reserve_satoshis.unwrap() {+ // If local is below the reserve on this new commitment, local balance MUST be greater than+ // or equal to local balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.0 = stats.local_balance_before_fee_msat;++ if stats.remote_balance_before_fee_msat / 1000 < funding.holder_selected_channel_reserve_satoshis {+ // If remote is below the reserve on this new commitment, remote balance MUST be greater than+ // or equal to remote balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.1 = stats.remote_balance_before_fee_msat;+ }
// This populates the HTLC-source table with the indices from the HTLCs in the commitment
// transaction.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 27bf59a to 44b59ceCompareFebruary 17, 2026 17:33
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
wpaulinoand others added 2 commits February 18, 2026 16:23
When we create the post-splice `FundingScope`, the monotonicity debug
assertion trackers were initialized to the post-splice balance without
accounting for pending HTLCs or anchor costs. Since splices can have
in-flight HTLCs (unlike fresh channel opens), the first commitment
transaction's actual balance was lower than the initialized max, causing
the debug assertion in `ChannelContext::build_commitment_transaction` to
fire.
Note that we don't need to recompute the full post-splice balance here.
We can rely on the pre-splice `FundingScope`'s
`holder/counterparty_max_commitment_tx_output` instead since they're
already accounted for there.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
These assertions made sure that our balance would never dip below the
reserve, and if they ever were, that the balance must only move towards
meeting the reserve. With splicing, this doesn't always work, as a node
that is not interested in contributing could end up below the reserve of
the post-splice channel. Therefore, we rework these assertions such that
we only keep track of the previous commitment transaction balance, and
compare against the current, ensuring that our balance only increases
when below the reserve.
@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 44b59ce to 034892bCompareFebruary 19, 2026 00:23

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks

@tankyleo
tankyleo merged commit 62c7575 into lightningdevkit:mainFeb 20, 2026
21 of 22 checks passed
@wpaulino
wpaulino deleted the fix-splice-funding-scope-max-commitment-output branch February 20, 2026 17:57
@jkczyzjkczyz mentioned this pull request Mar 19, 2026
50 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@tankyleo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Account for missing balance in splice max commitment output tracking - #4417

Merged
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output
Feb 20, 2026
Merged

Account for missing balance in splice max commitment output tracking#4417
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

When a splice creates new funding, the monotonicity debug assertion trackers were initialized to the raw post-splice balance without accounting for pending HTLCs or anchor costs. Since splices can have in-flight HTLCs (unlike fresh channel opens), the first commitment transaction's actual balance was lower than the initialized max, causing the debug assertion in ChannelContext::build_commitment_transaction to fire.

@wpaulinowpaulino added this to the 0.3 milestone Feb 13, 2026
@wpaulinowpaulino self-assigned this Feb 13, 2026
@ldk-reviews-bot

ldk-reviews-bot commented Feb 13, 2026

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Feb 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.91%. Comparing base (153e57e) to head (034892b).
⚠️ Report is 20 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #4417 +/- ##
=======================================
Coverage 85.90% 85.91% =======================================
Files 156 156 Lines 103965 103975 +10 Branches 103965 103975 +10 =======================================
+ Hits 89316 89332 +16 + Misses 12128 12119 -9 - Partials 2521 2524 +3 
FlagCoverage Δ
tests85.91% <100.00%> (+<0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the direction I have in mind what do you think ? We'd also assert that a balance that is under the new reserve did not decrease across the splice. Probably want to rename the state variables to highlight that once we are above the reserve, these track the balance on the previous commitment.

diff --git a/lightning/src/ln/channel.rs b/lightning/src/ln/channel.rs
index b8dc90ef9..8de424beb 100644
--- a/lightning/src/ln/channel.rs+++ b/lightning/src/ln/channel.rs@@ -2772,55 +2772,18 @@ impl FundingScope {
context.counterparty_dust_limit_satoshis,
);
- // Account for in-flight HTLCs and anchor outputs when initializing the max- // commitment tx output trackers. Unlike a fresh channel open (which has no HTLCs),- // a splice may have pending HTLCs whose amounts are subtracted from the balances- // in the commitment transaction. Without this adjustment, the monotonicity debug- // assertion in `build_commitment_transaction` would fire on the first commitment.- #[cfg(debug_assertions)]- let (local_balance_msat, remote_balance_msat) = {- let pending_outbound_htlcs_value_msat: u64 =- context.pending_outbound_htlcs.iter().map(|h| h.amount_msat).sum();- let pending_inbound_htlcs_value_msat: u64 =- context.pending_inbound_htlcs.iter().map(|h| h.amount_msat).sum();- let channel_type = &post_channel_transaction_parameters.channel_type_features;- let total_anchors_sat = if channel_type.supports_anchors_zero_fee_htlc_tx() {- ANCHOR_OUTPUT_VALUE_SATOSHI * 2- } else {- 0- };- let post_value_to_remote_msat =- (post_channel_value * 1000).saturating_sub(post_value_to_self_msat);- if post_channel_transaction_parameters.is_outbound_from_holder {- (- post_value_to_self_msat- .saturating_sub(pending_outbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- post_value_to_remote_msat.saturating_sub(pending_inbound_htlcs_value_msat),- )- } else {- (- post_value_to_self_msat.saturating_sub(pending_outbound_htlcs_value_msat),- post_value_to_remote_msat- .saturating_sub(pending_inbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- )- }- };-
Self {
channel_transaction_parameters: post_channel_transaction_parameters,
value_to_self_msat: post_value_to_self_msat,
funding_transaction: None,
counterparty_selected_channel_reserve_satoshis,
holder_selected_channel_reserve_satoshis,
+ // Here we copy over these values; if the party is below the reserve under the new funding+ // scope, their balance MUST NOT decrease.
#[cfg(debug_assertions)]
- holder_max_commitment_tx_output: Mutex::new((local_balance_msat, remote_balance_msat)),+ holder_max_commitment_tx_output: Mutex::new(prev_funding.holder_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(debug_assertions)]
- counterparty_max_commitment_tx_output: Mutex::new((- local_balance_msat,- remote_balance_msat,- )),+ counterparty_max_commitment_tx_output: Mutex::new(prev_funding.counterparty_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(any(test, fuzzing))]
next_local_fee: Mutex::new(PredictedNextFee::default()),
#[cfg(any(test, fuzzing))]
@@ -5544,12 +5507,21 @@ impl<SP: SignerProvider> ChannelContext<SP> {
} else {
funding.counterparty_max_commitment_tx_output.lock().unwrap()
};
- debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat || stats.local_balance_before_fee_msat / 1000 >= funding.counterparty_selected_channel_reserve_satoshis.unwrap());- broadcaster_max_commitment_tx_output.0 = cmp::max(broadcaster_max_commitment_tx_output.0, stats.local_balance_before_fee_msat);- debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat || stats.remote_balance_before_fee_msat / 1000 >= funding.holder_selected_channel_reserve_satoshis);- broadcaster_max_commitment_tx_output.1 = cmp::max(broadcaster_max_commitment_tx_output.1, stats.remote_balance_before_fee_msat);- }+ if stats.local_balance_before_fee_msat / 1000 < funding.counterparty_selected_channel_reserve_satoshis.unwrap() {+ // If local is below the reserve on this new commitment, local balance MUST be greater than+ // or equal to local balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.0 = stats.local_balance_before_fee_msat;++ if stats.remote_balance_before_fee_msat / 1000 < funding.holder_selected_channel_reserve_satoshis {+ // If remote is below the reserve on this new commitment, remote balance MUST be greater than+ // or equal to remote balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.1 = stats.remote_balance_before_fee_msat;+ }
// This populates the HTLC-source table with the indices from the HTLCs in the commitment
// transaction.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 27bf59a to 44b59ceCompareFebruary 17, 2026 17:33
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
wpaulinoand others added 2 commits February 18, 2026 16:23
When we create the post-splice `FundingScope`, the monotonicity debug
assertion trackers were initialized to the post-splice balance without
accounting for pending HTLCs or anchor costs. Since splices can have
in-flight HTLCs (unlike fresh channel opens), the first commitment
transaction's actual balance was lower than the initialized max, causing
the debug assertion in `ChannelContext::build_commitment_transaction` to
fire.
Note that we don't need to recompute the full post-splice balance here.
We can rely on the pre-splice `FundingScope`'s
`holder/counterparty_max_commitment_tx_output` instead since they're
already accounted for there.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
These assertions made sure that our balance would never dip below the
reserve, and if they ever were, that the balance must only move towards
meeting the reserve. With splicing, this doesn't always work, as a node
that is not interested in contributing could end up below the reserve of
the post-splice channel. Therefore, we rework these assertions such that
we only keep track of the previous commitment transaction balance, and
compare against the current, ensuring that our balance only increases
when below the reserve.
@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 44b59ce to 034892bCompareFebruary 19, 2026 00:23

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks

@tankyleo
tankyleo merged commit 62c7575 into lightningdevkit:mainFeb 20, 2026
21 of 22 checks passed
@wpaulino
wpaulino deleted the fix-splice-funding-scope-max-commitment-output branch February 20, 2026 17:57
@jkczyzjkczyz mentioned this pull request Mar 19, 2026
50 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@tankyleo
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Account for missing balance in splice max commitment output tracking - #4417

Merged
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output
Feb 20, 2026
Merged

Account for missing balance in splice max commitment output tracking#4417
tankyleo merged 2 commits into
lightningdevkit:mainfrom
wpaulino:fix-splice-funding-scope-max-commitment-output

Conversation

@wpaulino

Copy link
Copy Markdown
Contributor

When a splice creates new funding, the monotonicity debug assertion trackers were initialized to the raw post-splice balance without accounting for pending HTLCs or anchor costs. Since splices can have in-flight HTLCs (unlike fresh channel opens), the first commitment transaction's actual balance was lower than the initialized max, causing the debug assertion in ChannelContext::build_commitment_transaction to fire.

@wpaulinowpaulino added this to the 0.3 milestone Feb 13, 2026
@wpaulinowpaulino self-assigned this Feb 13, 2026
@ldk-reviews-bot

ldk-reviews-bot commented Feb 13, 2026

Copy link
Copy Markdown

👋 Thanks for assigning @TheBlueMatt as a reviewer!
I'll wait for their review and will help manage the review process.
Once they submit their review, I'll check if a second reviewer would be helpful.

@codecov

codecovBot commented Feb 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.91%. Comparing base (153e57e) to head (034892b).
⚠️ Report is 20 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #4417 +/- ##
=======================================
Coverage 85.90% 85.91% =======================================
Files 156 156 Lines 103965 103975 +10 Branches 103965 103975 +10 =======================================
+ Hits 89316 89332 +16 + Misses 12128 12119 -9 - Partials 2521 2524 +3 
FlagCoverage Δ
tests85.91% <100.00%> (+<0.01%)⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tankyleotankyleo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the direction I have in mind what do you think ? We'd also assert that a balance that is under the new reserve did not decrease across the splice. Probably want to rename the state variables to highlight that once we are above the reserve, these track the balance on the previous commitment.

diff --git a/lightning/src/ln/channel.rs b/lightning/src/ln/channel.rs
index b8dc90ef9..8de424beb 100644
--- a/lightning/src/ln/channel.rs+++ b/lightning/src/ln/channel.rs@@ -2772,55 +2772,18 @@ impl FundingScope {
context.counterparty_dust_limit_satoshis,
);
- // Account for in-flight HTLCs and anchor outputs when initializing the max- // commitment tx output trackers. Unlike a fresh channel open (which has no HTLCs),- // a splice may have pending HTLCs whose amounts are subtracted from the balances- // in the commitment transaction. Without this adjustment, the monotonicity debug- // assertion in `build_commitment_transaction` would fire on the first commitment.- #[cfg(debug_assertions)]- let (local_balance_msat, remote_balance_msat) = {- let pending_outbound_htlcs_value_msat: u64 =- context.pending_outbound_htlcs.iter().map(|h| h.amount_msat).sum();- let pending_inbound_htlcs_value_msat: u64 =- context.pending_inbound_htlcs.iter().map(|h| h.amount_msat).sum();- let channel_type = &post_channel_transaction_parameters.channel_type_features;- let total_anchors_sat = if channel_type.supports_anchors_zero_fee_htlc_tx() {- ANCHOR_OUTPUT_VALUE_SATOSHI * 2- } else {- 0- };- let post_value_to_remote_msat =- (post_channel_value * 1000).saturating_sub(post_value_to_self_msat);- if post_channel_transaction_parameters.is_outbound_from_holder {- (- post_value_to_self_msat- .saturating_sub(pending_outbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- post_value_to_remote_msat.saturating_sub(pending_inbound_htlcs_value_msat),- )- } else {- (- post_value_to_self_msat.saturating_sub(pending_outbound_htlcs_value_msat),- post_value_to_remote_msat- .saturating_sub(pending_inbound_htlcs_value_msat)- .saturating_sub(total_anchors_sat * 1000),- )- }- };-
Self {
channel_transaction_parameters: post_channel_transaction_parameters,
value_to_self_msat: post_value_to_self_msat,
funding_transaction: None,
counterparty_selected_channel_reserve_satoshis,
holder_selected_channel_reserve_satoshis,
+ // Here we copy over these values; if the party is below the reserve under the new funding+ // scope, their balance MUST NOT decrease.
#[cfg(debug_assertions)]
- holder_max_commitment_tx_output: Mutex::new((local_balance_msat, remote_balance_msat)),+ holder_max_commitment_tx_output: Mutex::new(prev_funding.holder_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(debug_assertions)]
- counterparty_max_commitment_tx_output: Mutex::new((- local_balance_msat,- remote_balance_msat,- )),+ counterparty_max_commitment_tx_output: Mutex::new(prev_funding.counterparty_max_commitment_tx_output.lock().unwrap().clone()),
#[cfg(any(test, fuzzing))]
next_local_fee: Mutex::new(PredictedNextFee::default()),
#[cfg(any(test, fuzzing))]
@@ -5544,12 +5507,21 @@ impl<SP: SignerProvider> ChannelContext<SP> {
} else {
funding.counterparty_max_commitment_tx_output.lock().unwrap()
};
- debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat || stats.local_balance_before_fee_msat / 1000 >= funding.counterparty_selected_channel_reserve_satoshis.unwrap());- broadcaster_max_commitment_tx_output.0 = cmp::max(broadcaster_max_commitment_tx_output.0, stats.local_balance_before_fee_msat);- debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat || stats.remote_balance_before_fee_msat / 1000 >= funding.holder_selected_channel_reserve_satoshis);- broadcaster_max_commitment_tx_output.1 = cmp::max(broadcaster_max_commitment_tx_output.1, stats.remote_balance_before_fee_msat);- }+ if stats.local_balance_before_fee_msat / 1000 < funding.counterparty_selected_channel_reserve_satoshis.unwrap() {+ // If local is below the reserve on this new commitment, local balance MUST be greater than+ // or equal to local balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.0 <= stats.local_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.0 = stats.local_balance_before_fee_msat;++ if stats.remote_balance_before_fee_msat / 1000 < funding.holder_selected_channel_reserve_satoshis {+ // If remote is below the reserve on this new commitment, remote balance MUST be greater than+ // or equal to remote balance on the previous commitment, even across a splice.+ debug_assert!(broadcaster_max_commitment_tx_output.1 <= stats.remote_balance_before_fee_msat);+ }+ broadcaster_max_commitment_tx_output.1 = stats.remote_balance_before_fee_msat;+ }
// This populates the HTLC-source table with the indices from the HTLCs in the commitment
// transaction.

@ldk-reviews-bot

Copy link
Copy Markdown

👋 The first review has been submitted!

Do you think this PR is ready for a second reviewer? If so, click here to assign a second reviewer.

@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 27bf59a to 44b59ceCompareFebruary 17, 2026 17:33
Comment threadlightning/src/ln/channel.rs
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/channel.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
Comment threadlightning/src/ln/splicing_tests.rs Outdated
wpaulinoand others added 2 commits February 18, 2026 16:23
When we create the post-splice `FundingScope`, the monotonicity debug
assertion trackers were initialized to the post-splice balance without
accounting for pending HTLCs or anchor costs. Since splices can have
in-flight HTLCs (unlike fresh channel opens), the first commitment
transaction's actual balance was lower than the initialized max, causing
the debug assertion in `ChannelContext::build_commitment_transaction` to
fire.
Note that we don't need to recompute the full post-splice balance here.
We can rely on the pre-splice `FundingScope`'s
`holder/counterparty_max_commitment_tx_output` instead since they're
already accounted for there.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
These assertions made sure that our balance would never dip below the
reserve, and if they ever were, that the balance must only move towards
meeting the reserve. With splicing, this doesn't always work, as a node
that is not interested in contributing could end up below the reserve of
the post-splice channel. Therefore, we rework these assertions such that
we only keep track of the previous commitment transaction balance, and
compare against the current, ensuring that our balance only increases
when below the reserve.
@wpaulino
wpaulinoforce-pushed the fix-splice-funding-scope-max-commitment-output branch from 44b59ce to 034892bCompareFebruary 19, 2026 00:23

@TheBlueMattTheBlueMatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks

@tankyleo
tankyleo merged commit 62c7575 into lightningdevkit:mainFeb 20, 2026
21 of 22 checks passed
@wpaulino
wpaulino deleted the fix-splice-funding-scope-max-commitment-output branch February 20, 2026 17:57
@jkczyzjkczyz mentioned this pull request Mar 19, 2026
50 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@wpaulino@ldk-reviews-bot@TheBlueMatt@tankyleo