Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Set correct counterparty_spendable_height on c.p. revoked HTLCs #3564

Merged

Conversation

TheBlueMatt
Copy link
Collaborator

If the counterparty broadcasts a revoked transaction with offered
HTLCs, the output is not immediately pinnable as the counterparty
cannot claim the HTLC until the CLTV expires and they use an
HTLC-Timeout path.

`counterparty_spendable_height` is not used outside of `package.rs`
so there's not much reason to have an accessor for it. Also, in the
next commit an issue with setting the correct value for revoked
counterparty HTLC outputs is fixed, and the upgrade path causes the
value to be 0 in some cases, making using the value in too many
places somewhat fraught.
@TheBlueMatt TheBlueMatt force-pushed the 2025-01-revoked-htlc-not-pinnable branch from 80fd088 to 215995c Compare January 27, 2025 18:25
Copy link
Contributor

@morehouse morehouse left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice!

The griefing attack detailed here actually exploits this bug. But after #3340 the bug became less harmful, and I forgot to create an issue to track this.

Glad to see this fixed properly now!

@morehouse
Copy link
Contributor

This basically LGTM. Willing to approve after the misleading comment on the functional tests is fixed.

@TheBlueMatt TheBlueMatt force-pushed the 2025-01-revoked-htlc-not-pinnable branch from 901fe7b to b4f85e4 Compare January 28, 2025 14:56
Copy link
Contributor

@morehouse morehouse left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM pending squash

If the counterparty broadcasts a revoked transaction with offered
HTLCs, the output is not immediately pinnable as the counterparty
cannot claim the HTLC until the CLTV expires and they use an
HTLC-Timeout path.

Here we fix the `counterparty_spendable_height` value we set on
counterparty revoked HTLC claims to match reality. Note that
because we still consider these outputs `Pinnable` the value is
not used. In the next commit we'll start making them `Unpinnable`
which will actually change behavior.

Note that when upgrading we have to wipe the
`counterparty_spendable_height` value for non-offered HTLCs as
otherwise we'd consider them `Unpinnable` when they are, in fact,
`Pinnable`.
If the counterparty broadcasts a revoked transaction with offered
HTLCs, the output is not immediately pinnable as the counterparty
cannot claim the HTLC until the CLTV expires and they use an
HTLC-Timeout path.

Here we properly set these packages as `Unpinnable`, changing some
transaction generation during tests.
@TheBlueMatt
Copy link
Collaborator Author

Squashed.

@TheBlueMatt TheBlueMatt force-pushed the 2025-01-revoked-htlc-not-pinnable branch from b4f85e4 to 6c57a1f Compare January 28, 2025 20:39
@TheBlueMatt TheBlueMatt merged commit 1434e9c into lightningdevkit:main Jan 30, 2025
25 checks passed
Copy link

@SupavineeSerksiri6315 SupavineeSerksiri6315 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ขอบพระคุณมากค่ะ

@TheBlueMatt
Copy link
Collaborator Author

Backported in #3613

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants