Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Failure to reject absurdly high channel reserves

Aperta
#9,475 0 commenti 1 reazione 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 2 giorni

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
65/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
c
Ambito
payments

Direzione di ricerca

Inizia in openingd/common.c, intorno al controllo della riserva aggregata alle righe 126-144, e segui la convalida dell’apertura del canale per channel_reserve_satoshis. Conferma che i parametri forniti vengano rifiutati quando entrambi i saldi sono inferiori alla riserva e verifica il comportamento del limite della riserva della controparte rispetto ai limiti suggeriti nell’issue.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

BOLT 2 has one required and one suggested check that provide an upper limit on the channel reserve imposed by the counterparty:

  1. The receiving node MUST fail the channel if:
      - both `to_local` and `to_remote` amounts for the initial commitment transaction are less than or equal to `channel_reserve_satoshis`
    
  2. The receiving node MAY fail the channel if:
      - it considers `channel_reserve_satoshis` too large.
    

CLN implements neither.

Impact

CLN will accept a channel reserve larger than its own initial balance, leaving it unable to send anything on the channel until the funder chooses to push more funds to it. For example, CLN accepts the following channel parameters:

funding_satoshis = 100_000
push_msat = 20_000_000
feerate_per_kw = 500
channel_reserve_satoshis = 87_000
channel_type = anchors

The balances on the initial commitment transaction after fees are:

to_local (funder) = 78_778 sat
to_remote (CLN) = 20_000 sat

Both sides are below the reserve, so CLN cannot spend until it has received a further sats, and the funder is under no obligation to ever send it. CLN's balance is still recoverable on-chain by closing the channel.

One thing to note is that CLN does impose the aggregate reserve check on the funding amount: https://github.com/ElementsProject/lightning/blob/c1551c557cc524e2241f9cbae7d3895b1b0b627c/openingd/common.c#L126-L144 This rejects cases where aggregate reserve/fee exceeds the channel capacity, but misses cases where the capacity covers the fee and reserve, yet after pushing some amount to the peer, both balances fall below the reserve.

Suggested fix

Add a check for requirement 1 above, as mandated by the spec.

Also add a cap on the channel reserve imposed by the counterparty. For reference, LND caps at 20% of capacity and Eclair caps at 5%.

Discovery

The missing specification check was detected while fuzzing with smite.

Lingua principale
C
Stelle
3.1k
Fork
1k
Merge medio
3g 10h
PR unite (30g)
40

Preparare l'ambiente

  • Include un Dockerfile o un file Docker Compose
  • Ha un modello di pull request
  • Nessuna guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di ElementsProject/lightning

Tutte le issue di ElementsProject/lightning

Issue simili

Altre issue su C

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.