Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Failure to reject `option_scid_alias` on an announced channel

Đang mở
#9,444 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 2 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
65/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
c

Hướng nghiên cứu

Bắt đầu tại channel_type_accept() và theo dõi cách channel_flags được truyền qua các luồng funding của openingd và dualopend. Tái hiện trường hợp của giao thức funding v1 trong đó một open_channel được thông báo đặt option_scid_alias, sử dụng phát hiện fuzzing của smite làm ngữ cảnh. Hoàn thành khi tổ hợp không hợp lệ bị từ chối lúc nhận, trong khi các loại channel hợp lệ vẫn tiếp tục qua giao thức.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

BOLT 2 forbids the sender of open_channel from setting the option_scid_alias bit in channel_type when announce_channel is true:

The sending node:

  • if it includes open_channel_tlvs:
    • MUST set channel_type:
      • if announce_channel is true (not 0):
        • MUST NOT send channel_type with the option_scid_alias bit set.

CLN never generates this combination as opener, but it does not reject it on receipt: channel_type_accept() never sees channel_flags, so the fundee happily replies with accept_channel echoing back option_scid_alias on a channel it will then announce. The spec does not specify rules for the acceptor in this case, so accepting it is not itself a violation, but the resulting channel is internally inconsistent.

Impact

Both openingd and dualopend are affected. The effect is that both can exchange announcement_signatures and publicly announce the channel using its real short_channel_id. However, per BOLT, when the agreed channel type has option_scid_alias set, a node MUST NOT allow incoming HTLCs to that channel using the real short_channel_id. So if the peer returns its signatures, CLN ends up announcing a channel to the whole network and then refusing every HTLC (addressed to that short_channel_id) it is asked to forward to the peer, which only affects the peer.

Only forwards towards the peer are affected, inbound HTLCs still work. For CLN, this means gaining some bad reputation for unnecessarily failing HTLCs. Other than that, this is purely a spec-compliance issue.

Discovery

This bug was found while fuzzing the v1 funding protocol with smite.

Ngôn ngữ chính
C
Star
3.1k
Fork
1k
Merge trung bình
3 ngày 10 giờ
Pull request đã merge (30 ngày)
40

Chuẩn bị môi trường

  • Có Dockerfile hoặc tệp Docker Compose
  • Có mẫu pull request
  • Không có hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của ElementsProject/lightning

Tất cả issue của ElementsProject/lightning

Issue tương tự

Thêm issue về C

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.