Add support for fulfillment payload #3321
Draft
t-bast wants to merge 3 commits into
Draft
Conversation
We refactor the attribution data code to make it more consistent with the rest of the Sphinx-related code. We add comments and intermediate variables to make it more readable. We introduce intermediate classes to hold data and add better symmetry between the success and failure cases. This will make it easier to implement trampoline attribution and add fulfillment data (lightning/bolts#1344).
We correctly extract shared secrets (including trampoline shared secrets) and detect when we're inside a blinded path to avoid including attribution data. Note that we don't use the trampoline shared secret yet, since full trampoline isn't implemented (see #2819 for the full changes). We add tests for attribution data with blinded paths and trampoline payments.
6244b93 to
b78ce34
Compare
This adds support for including a payload in `update_fulfill_htlc` that the recipient encrypts for the payer. This can be useful to transmit data atomically with the fulfillment of a payment. The main challenge is that intermediate nodes may drop or tamper with this fulfillment payload, which is why we include it in the HMACs of the attribution data, which lets senders detect which pair of nodes may be malicious. See lightning/bolts#1344
b78ce34 to
16130a1
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This adds support for including a payload in
update_fulfill_htlcthat the recipient encrypts for the payer. This can be useful to transmit data atomically with the fulfillment of a payment. The main challenge is that intermediate nodes may drop or tamper with this fulfillment payload, which is why we include it in the HMACs of the attribution data, which lets senders detect which pair of nodes may be malicious.See lightning/bolts#1344 for the detailed specification.
We don't currently include any fulfillment payload when we're the final node, but we correctly relay fulfillment payloads from downstream and correctly decrypt them when we're the sender. When we start including a fulfillment payload as the final node, we should also:
Builds on top of #3320