Failure to reject absurdly high channel reserves
Maintainer thường phản hồi trong vòng 2 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 65/100
Hướng nghiên cứu
Bắt đầu trong openingd/common.c, tại phần kiểm tra khoản dự trữ tổng hợp quanh các dòng 126-144, và lần theo quá trình xác thực mở kênh cho channel_reserve_satoshis. Xác nhận rằng các tham số được cung cấp bị từ chối khi cả hai số dư đều thấp hơn khoản dự trữ, đồng thời kiểm tra hành vi giới hạn khoản dự trữ của đối tác dựa trên các giới hạn được đề xuất trong issue.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
BOLT 2 has one required and one suggested check that provide an upper limit on the channel reserve imposed by the counterparty:
-
The receiving node MUST fail the channel if: - both `to_local` and `to_remote` amounts for the initial commitment transaction are less than or equal to `channel_reserve_satoshis` -
The receiving node MAY fail the channel if: - it considers `channel_reserve_satoshis` too large.
CLN implements neither.
Impact
CLN will accept a channel reserve larger than its own initial balance, leaving it unable to send anything on the channel until the funder chooses to push more funds to it. For example, CLN accepts the following channel parameters:
funding_satoshis = 100_000
push_msat = 20_000_000
feerate_per_kw = 500
channel_reserve_satoshis = 87_000
channel_type = anchors
The balances on the initial commitment transaction after fees are:
to_local (funder) = 78_778 sat
to_remote (CLN) = 20_000 sat
Both sides are below the reserve, so CLN cannot spend until it has received a further sats, and the funder is under no obligation to ever send it. CLN's balance is still recoverable on-chain by closing the channel.
One thing to note is that CLN does impose the aggregate reserve check on the funding amount: https://github.com/ElementsProject/lightning/blob/c1551c557cc524e2241f9cbae7d3895b1b0b627c/openingd/common.c#L126-L144 This rejects cases where aggregate reserve/fee exceeds the channel capacity, but misses cases where the capacity covers the fee and reserve, yet after pushing some amount to the peer, both balances fall below the reserve.
Suggested fix
Add a check for requirement 1 above, as mandated by the spec.
Also add a cap on the channel reserve imposed by the counterparty. For reference, LND caps at 20% of capacity and Eclair caps at 5%.
Discovery
The missing specification check was detected while fuzzing with smite.
- Ngôn ngữ chính
- C
- Star
- 3.1k
- Fork
- 1k
- Merge trung bình
- 4 ngày 2 giờ
- Pull request đã merge (30 ngày)
- 45
Chuẩn bị môi trường
- Có Dockerfile hoặc tệp Docker Compose
- Có mẫu pull request
- Không có hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của ElementsProject/lightning
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
ElementsProject/lightning#9593 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
ElementsProject/lightning#9322 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
ElementsProject/lightning#9206 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
ElementsProject/lightning#9187 · 1 bình luận · 1 reaction ·
Maintainer thường phản hồi trong vòng 2 ngày
-
QA
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
ElementsProject/lightning#9117 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của ElementsProject/lightning
Issue tương tự
-
Bad device URI "://" on network printers. Printing stopped working between 2.4.19 and 2.4.20Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
OpenPrinting/cups#1751 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Warps 4 unit tests (raalloc)Đang mởenhancement good first issue
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
Maintainer thường phản hồi trong vòng 1 ngày
-
compile: jv_mem_calloc assertion abort after "too many function parameters" error in a nested functionCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Policy query leaks host primary block (BSL_PrimaryBlock_deinit skipped) on two early-exit pathsĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
NASA-AMMOS/BSL#355 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
arancormonk/dsd-neo#660 ·
Maintainer thường phản hồi trong vòng 1 ngày