LDK
← All projectsLightning Dev Kit

rust-lightning

Composable Rust libraries for building Lightning wallets, nodes, and services.

BitcoinCryptographic librariesLightning NetworkNormal
Repository coverage

1478 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

225security candidates208second-pass queue546AI analyses
61commits · 30 days
191commits · 60 days
647commits · 180 days
1475commits · 365 days
Backfill bands
Aug 5 → Feb 6819 seen18 candidatesComplete
Feb 6 → Jun 6468 seen16 candidatesComplete
Jun 6 → Jul 6128 seen8 candidatesComplete
Jul 6 → Aug 561 seen3 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

69/100 average clarity
352Strong · 80–100
782Adequate · 60–79
285Thin · 40–59
59Opaque · 0–39
3security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Elias Rohrer1531546567
Matt Corallo35647114273
Jeffrey Czyz1774163168
Leo Nash1161369162
Valentine Wallace1351021169
Vincenzo Palazzo1028184
Wilmer Paulino1493964069
Joost Jager1622490069
elnosh301319056
shaavan2267069
Carla Kirk-Cohen6539069
benthecarman1834071
Analysis record

Published AI watches

Last scanned 21 minutes ago

Low 32 AI analysisMessage 91 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Merge PR 'Only fetch TXIDs instead of entire block during gossip verification' (#4846)

This commit changes how the Lightning Dev Kit's block-sync module verifies Lightning network gossip announcements. Instead of downloading entire Bitcoin blocks (which can be large), it now downloads only the list of transaction IDs for a b…

API surface change in UtxoSource traitReduced data exposure: no longer fetches full blocks for gossip verificationNew JSON parsing for txid lists and TxOut values
ebe7a447by Matt Corallo+275−1025 files
No security note in commit
Low 35 AI analysisMessage 81 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Merge PR 'Allow filtered block rescans at the current tip' (#4847)

This commit changes how the Lightning Dev Kit (LDK) node software handles receiving the same block twice through its filtered-block interface. Previously, calling filtered_block_connected with the current tip again would trigger an asserti…

Assertion relaxation in block connection pathPotential denial-of-service vector removed: previously a malicious or buggy filter provider could crash the node by replaying the current tipNew test coverage for same-block filtered rescan
54ddbd0bby Matt Corallo+177−486 files
No security note in commit
Informational 15 AI analysisMessage 83 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Add test framework coverage of `Listen` block connection replays

This commit only adds a new test mode to the project's internal testing framework. It lets developers simulate a specific way blocks are delivered to the Lightning node (a 'replay' through the Listen interface) so that behavior is covered …

bf6ad23eby Matt Corallo+18−32 files
No security note in commit
Informational 15 AI analysisMessage 83 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Update functional test block connection to detect block replays

This commit changes only internal test helper code in the Lightning Dev Kit repository. It makes the functional test framework smarter about 'block replays'—situations where the same block is fed to a test node more than once—so the fake b…

No production code modifiedNo cryptographic, consensus, or networking changesCommit message frames change as test-framework correctness, not security
477facb4by Matt Corallo+41−333 files
No security note in commit
Moderate 66 AI analysisMessage 73 · Adequate
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Correct HTLC confusion on unrevoked counterparty commitment txs

This patch fixes a bug in the Lightning Dev Kit where the software could confuse HTLCs (payment contracts) on live, unrevoked counterparty commitment transactions with ones from old, revoked transactions. Previously, it relied only on whet…

Incorrect revocation state detection for counterparty commitment transactionsHTLC direction not previously checked when matching against pending HTLCsPromotion of debug assertions to full assertions for HTLC claim path consistency
f06a08a6by Matt Corallo+26−192 files
Vendor flagged security relevance
Low 47 AI analysisMessage 85 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Return `Err`s` instead of panicking on oversized messages

This commit changes how the Lightning networking code handles oversized encrypted messages. Previously, certain conditions would cause the program to crash with a panic. Now the code returns errors instead, which is a defensive improvement…

panic-to-error conversion for oversized message encryption/decryptiondenial-of-service hardening against oversized peer messagesdebug_assert retained to preserve test coverage of invariant violations
08f12bc7by Matt Corallo+68−313 files
Vendor flagged security relevance
Moderate 62 AI analysisMessage 85 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Avoid panicking when attempting to send an oversized message

This commit fixes a crash bug in the Lightning Dev Kit's peer message handling. Previously, if a message grew too large to be sent over the encrypted peer connection, the code would panic (abruptly terminate the whole program). The patch m…

Replaces a `.expect()` panic path with a fallible `Result` in peer message encryptionAdds graceful peer disconnection when a critical message cannot be sentIncludes a regression test for oversized-message handling
c5fdc3bfby Matt Corallo+148−901 file
Vendor flagged security relevance
High 74 AI analysisMessage 78 · Adequate
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Avoid oversized relayed failure messages

This patch fixes a crash bug in the Lightning Dev Kit's handling of HTLC failure messages. A downstream peer could send a maximally-sized failure message without attribution data. When the node added its own attribution data while relaying…

Denial-of-service via remote-triggered panic in message encryptionOversized message exceeding Noise/Lightning wire framing limitMissing length validation before adding attribution data during relay
6b1dfb1aby Matt Corallo+64−191 file
Vendor flagged security relevance
Moderate 64 AI analysisMessage 83 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Reject attempts to advance one-hop blinded forward paths

This commit fixes a denial-of-service bug in rust-lightning where a maliciously crafted one-hop blinded reply path could cause the node to panic when it tried to respond. The fix rejects paths with too few hops before advancing them, and a…

Denial-of-service vector via malformed blinded pathPanic in onion construction due to zero-hop pathUntrusted reply path input validation gap
969a40cfby Matt Corallo+49−14 files
Vendor flagged security relevance
High 72 AI analysisMessage 96 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

lightning-types: replace Zl/Zp separators in `PrintableString`

This commit fixes a log-forgery risk in a Rust Lightning library helper called PrintableString. That helper is meant to make untrusted text safe to print by replacing dangerous characters with a placeholder. It already caught most control …

log injection / log forgery via U+2028/U+2029 line separatorsincomplete input sanitisation in PrintableStringpeer-controlled strings (node alias, BOLT 12 description/issuer/payer_note, peer_msg) as attack surface
75defa9cby Vincenzo Palazzo+63−83 files
Vendor flagged security relevance
Moderate 69 AI analysisMessage 73 · Adequate
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Apply the unfunded channel peer limit to all unaccepted channels

This commit fixes a rate-limiting bug in the Lightning Dev Kit (LDK) that let a single peer bypass the cap on how many different peers can have unfunded (not-yet-funded) channels open. Previously, if a peer sent multiple channel requests q…

Denial-of-service resource exhaustion via rapid inbound channel open requestsLogic error in rate-limiting conditionRegression test added for the bypass scenario
56a4ee43by Matt Corallo+87−62 files
Vendor flagged security relevance
Moderate 60 AI analysisMessage 88 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Allow filtered block rescans at the current tip

This commit fixes a bug where replaying the current blockchain block through a normal listener callback could crash two core Lightning components (ChannelManager and OutputSweeper) with a panic. The fix recognizes a same-block replay as a …

panic in chain listener callbacksame-block replay/rescan mishandlingassertion failure on valid chain input
686f9860by Elias Rohrer+118−123 files
Vendor flagged security relevance
Moderate 57 AI analysisMessage 78 · Adequate
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Avoid panic when reorged claims cannot merge

This commit fixes a crash bug in the Lightning Dev Kit's on-chain transaction handler. During a deep blockchain reorganization, a previously settled HTLC claim could be 'resurrected' at a block height where it could no longer be combined w…

Assertion/panic in reorg handling pathDeep blockchain reorg as trigger conditionHTLC claim resurrection after reorg
f1dc8487by Matt Corallo+219−52 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 45 · Thin
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Update crate repository links to forgejo

This commit simply updates the 'repository' web links in 15 package metadata files from GitHub to a self-hosted Forgejo instance. It does not change any program code, build logic, dependencies, or security behavior. There is no security is…

eb77676dby benthecarman+15−1515 files
No security note in commit
Moderate 54 AI analysisMessage 73 · Adequate
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Retransmit splice_locked for 0-conf channels missing tx_signatures

This commit fixes a bug in the Lightning Dev Kit where, after a disconnection, a node could fail to retransmit a 'splice_locked' message to a peer that was still waiting for transaction signatures. Without this retransmission, the two peer…

Protocol state desynchronization between channel peers after reconnectionMissing retransmission of splice_locked for 0-conf splice channelsPotential channel unusability or stuck splice negotiation
5434015bby Wilmer Paulino+266−12 files
No security note in commit
Low 37 AI analysisMessage 83 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

bolt12: add pay_for_bolt12_invoice for externally-sourced invoices

This commit adds a new API, pay_for_bolt12_invoice, that lets users pay a BOLT 12 invoice even if LDK did not originally request it. It is intended for advanced use cases like multi-sender payments and replaces an older, more restrictive A…

New API removes internal invoice-origin verification, shifting trust boundary to callerDocumentation explicitly warns caller to verify invoice via Bolt12Invoice::verify_using_metadata and to ensure unique payment_id to avoid duplicate paymentsInput validation added for zero amount, overpay, and partial-amount-without-MPP
5b80fe9cby Alkamal01+550−156 files
No security note in commit
Low 26 AI analysisMessage 90 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Include to_self_delay size in DelayedPaymentOutput weight calculation

This commit fixes a small accounting bug in how the Lightning wallet estimates the size (and therefore transaction fee) of a special Bitcoin transaction that sweeps funds back to the user after a channel closes. The old code always assumed…

debug assertion failure possible in development/testing buildstransaction weight/fee estimate overestimation up to 3 WUconstant replaced with per-descriptor length computation
e6652237by Matt Morehouse+97−83 files
No security note in commit
Informational 18 AI analysisMessage 65 · Adequate
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

Correct docs on `ChannelSigner::get_per_commitment_point`

This commit only updates documentation comments for a Rust function called get_per_commitment_point. It removes an outdated warning that the method was non-asynchronous and that returning an error could cause a crash, and replaces it with …

Documentation-only changeRemoves outdated panic warningAdds retry/unblock guidance for signer errors
5057809bby Matt Corallo+6−31 file
No security note in commit
Informational 17 AI analysisMessage 83 · Strong
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

fuzz: allow empty-channel force close with in-flight payments

This commit changes a fuzz-testing harness, not the production Lightning node code. It loosens a test rule so the fuzzer can simulate force-closing a channel that has no pending payments of its own, even if other channels in the test still…

Fuzz harness behavior change onlyNo modifications to production consensus, cryptography, or networking codeNo privilege boundary crossed
dbb12502by Joost Jager+32−71 file
No security note in commit
Informational 12 AI analysisMessage 78 · Adequate
LDK Lightning Dev Kitrust-lightning BitcoinCryptographic librariesLightning Network

fuzz: require expected payment failures

This commit is a fuzz-test hardening change, not a fix for a live security bug. It makes an internal test harness stricter about when a simulated Lightning payment is allowed to fail, so the fuzzer can catch unexpected failure paths. It do…

Fuzz-test harness hardening onlyNo production code paths changedNo real-fund handling modified
090181b1by Joost Jager+179−81 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateUse SignedAmount::unsigned_abs to avoid overflowby Jeffrey Czyz · 2d948fdd · Feb 4, 2026 · 1 fileMessage 85 · StrongLow 34Details
Commit message · Jeffrey Czyz

Use SignedAmount::unsigned_abs to avoid overflow

In debug mode, using SignedAmount::abs can lead to an integer overflow
when used with SignedAmount::MIN. Use SignedAmount::unsigned_abs to
avoid this.

85/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Names security-relevant behavior explicitly
Why it was queued
memory safety
AI analysis · Low 34/100

This commit fixes a potential integer overflow bug in the Lightning Dev Kit's channel splicing code. The bug occurs when converting a negative Bitcoin amount to its absolute value in debug builds, which could crash the program. The fix uses a safer method that cannot overflow. The practical security impact is limited because the overflow only happens in debug mode and the affected values are normally constrained by protocol rules.

AI review queuedCorrect crate version numbers that have broken semverby Matt Corallo · 784b85c1 · Feb 3, 2026 · 10 filesMessage 73 · AdequateInformational 15Details
Commit message · Matt Corallo

Correct crate version numbers that have broken semver

The semver CI check is great but only checks the immediate crate in
question. It doesn't catch that many of our crates depend on
`lightning` and thus have actually broken semver as the types they
use have changed to `lightning` 0.3.

Here we hump the version of crates that have actually changed
semver since 0.2.

In addition to those that depend on `lightning`,
`lightning-invoice`'s API has changed (but was not being checked by
the semver CI task).

Finally, `lightning-macros` was updated to 0.2.1, so the version is
changed to 0.2.2.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only changes version numbers in package configuration files (Cargo.toml). It bumps crate versions from 0.2.x to 0.3.x to keep them aligned with semantic versioning rules after the underlying `lightning` crate changed its public types. There is no code change, no bug fix, and no security patch.

Security candidateFix 0.2 CHANGELOG to note that offers will break on downgradeby Matt Corallo · e245c0aa · Feb 3, 2026 · 1 fileMessage 73 · AdequateInformational 18Details
Commit message · Matt Corallo

Fix 0.2 CHANGELOG to note that offers will break on downgrade

It turns out we also switched the key we use to authenticate offers
*created* in the 0.2 upgrade and as a result downgrading to 0.2
will break any offers created on 0.2. This wasn't intentional but
it doesn't really seem worth fixing at this point, so just document
it.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
update trustdocumentation-only discount
AI analysis · Informational 18/100

This commit is a documentation-only update to the 0.2 release CHANGELOG. It adds a note warning users that if they upgrade to LDK 0.2, create BOLT 12 offers, and then downgrade to an older LDK version, those offers will not be accepted. This is a compatibility/operational issue, not a security vulnerability, and no code behavior is changed.

Security candidateAdd AChainMonitor trait and use it in background processorby Joost Jager · 4800a473 · Feb 3, 2026 · 2 filesMessage 73 · AdequateInformational 15Details
Commit message · Joost Jager

Add AChainMonitor trait and use it in background processor

Add a new `AChainMonitor` trait following the same pattern as
`AChannelManager`. This trait provides associated types for all
generic parameters of `ChainMonitor` and a `get_cm()` method to
access the underlying `ChainMonitor`.

Update the background processor to use `AChainMonitor` trait bounds
instead of spelling out the full `ChainMonitor` generic parameters.
This simplifies the function signatures by removing 5-6 explicit
generic parameters (CF, T, F, P, ES) per function.

This is preparation for adding a flush method to the AChainMonitor
trait.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing boundary
AI analysis · Informational 15/100

This commit is a pure internal refactoring in the Lightning Dev Kit Rust library. It introduces a new helper trait called AChainMonitor that wraps the existing ChainMonitor type, and updates background-processor functions to use that trait instead of listing many generic type parameters directly. There is no change to user-visible behavior, no bug fix, and no security-sensitive logic change.

AI review queuedAdd Utxo::new_v1_p2trby Willem Van Lint · 1f6095b5 · Feb 2, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Willem Van Lint

Add Utxo::new_v1_p2tr

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit adds a new helper function to create a UTXO descriptor for modern Taproot (P2TR) single-key spending. It is purely additive API surface with no changes to existing behavior, no bug fixes, and no security-sensitive logic beyond correctly estimating transaction weight for fee calculations.

AI review queuedDrop unused importsby Elias Rohrer · 0715f4aa · Feb 2, 2026 · 2 filesMessage 28 · OpaqueInformational 15Details
Commit message · Elias Rohrer

Drop unused imports

Co-Authored-By: HAL 9000

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply removes two unused import statements from Rust source files. It does not change any program logic, data handling, or security behavior. There is no security relevance.

AI review queuedRefactor `BroadcasterInterface` to include `TransactionType`by Elias Rohrer · 988f1b14 · Feb 2, 2026 · 11 filesMessage 73 · AdequateInformational 21Details
Commit message · Elias Rohrer

Refactor `BroadcasterInterface` to include `TransactionType`

Add a `TransactionType` enum to provide context about the type of
transaction being broadcast. This information can be useful for
logging, filtering, or prioritization purposes.

The `TransactionType` variants are:
- `Funding`: A funding transaction establishing a new channel
- `CooperativeClose`: A cooperative close transaction
- `UnilateralClose`: A force-close transaction
- `AnchorBump`: An anchor transaction for CPFP fee-bumping
- `Claim`: A transaction claiming outputs from commitment tx
- `Sweep`: A transaction sweeping spendable outputs to wallet

Co-Authored-By: HAL 9000
Signed-off-by: Elias Rohrer <dev@tnull.de>

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit is a straightforward API refactor: it adds a TransactionType label (Funding, Close, Claim, Sweep, etc.) to every place in the Lightning Dev Kit that broadcasts a Bitcoin transaction. The actual transactions being broadcast do not change; only the metadata passed alongside them changes. There is no security vulnerability being fixed or introduced here.

Security candidateAdd test coverage for `TransactionType::Splice`by Elias Rohrer · 32a801ef · Feb 2, 2026 · 8 filesMessage 78 · AdequateInformational 15Details
Commit message · Elias Rohrer

Add test coverage for `TransactionType::Splice`

Add parallel `txn_types` vector to `TestBroadcaster` to track
`TransactionType` alongside broadcast transactions. Existing
`txn_broadcast()` API remains unchanged for backward compatibility.
New `txn_broadcast_with_types()` API allows tests to verify transaction
types.

Also add a `clear()` helper method and update test files to use it
instead of directly manipulating `txn_broadcasted`, ensuring the two
vectors stay in sync.

Update splice tests to use the new API and verify that splice
transactions are broadcast with the correct `TransactionType`.

Co-Authored-By: HAL 9000
Signed-off-by: Elias Rohrer <dev@tnull.de>

78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
boot or update path
AI analysis · Informational 15/100

This commit only adds and improves test code. It gives the project's test mock broadcaster the ability to remember what 'type' each broadcast transaction was (for example, a splice transaction), and updates tests to check that splice transactions are labeled correctly. There is no change to production code that handles real money or network messages, so it does not introduce or fix a security vulnerability on its own.

Security candidateExport `outbound_payments` directly rather than via re-exportsby Matt Corallo · 0bc5c954 · Feb 2, 2026 · 28 filesMessage 85 · StrongInformational 19Details
Commit message · Matt Corallo

Export `outbound_payments` directly rather than via re-exports

Every time we use re-exports to hide a module in the public API we
end up accidentally breaking the public API due to accidental
seals. We did this yet again in
e9c6bbccc3ccd4cb121a092229f50e29b3345552 where we moved to using a
`CustomTlvs` field in the public API for `RecipientOnionFields` but
forgot to re-export it, making it impossible to use downstream.

Instead, here, we just actually export `outbound_payments`.

Compilation fixes by Claude.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
signing or wallet pathboot or update path
AI analysis · Informational 19/100

This commit is a straightforward code cleanup in a Rust Lightning library. It stops hiding an internal module behind re-exports and exposes it directly in the public API. The change fixes an earlier accidental break in the public API where a type (CustomTlvs) was used in a public struct but not re-exported, making it hard for downstream developers to use. There is no runtime security issue, no bug fix in payment logic, and no exploit.

AI review queuedResolve optional hash map TLV fields during ChannelManagerData deserializationby Joost Jager · 9a05daf3 · Feb 2, 2026 · 1 fileMessage 73 · AdequateInformational 24Details
Commit message · Joost Jager

Resolve optional hash map TLV fields during ChannelManagerData deserialization

Move the unwrap_or_else(new_hash_map) resolution for pending_intercepted_htlcs
and decode_update_add_htlcs from stage 2 (from_channel_manager_data) to stage 1
(ChannelManagerData::read). This changes the struct fields from Option<HashMap>
to HashMap, making it explicit that these are always present after deserialization.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 24/100

This commit is a small internal cleanup in the Lightning Dev Kit's channel manager. It moves the handling of two optional hash-map fields from a later processing stage into the deserialization stage, so the fields are always plain hash maps after loading. The change makes the code's invariants clearer and removes a potential source of inconsistency, but it does not appear to fix an active security bug on its own.

AI review queuedResolve legacy TLV fields during ChannelManagerData deserializationby Joost Jager · d2c55dd2 · Feb 2, 2026 · 1 fileMessage 73 · AdequateLow 28Details
Commit message · Joost Jager

Resolve legacy TLV fields during ChannelManagerData deserialization

Move the resolution of legacy/compatibility TLV fields from
from_channel_manager_data (stage 2) into ChannelManagerData::read
(stage 1). This keeps ChannelManagerData minimal by consolidating
mutually exclusive fields into their final form during deserialization:

- pending_outbound_payments: Merge TLV 3, TLV 1 (no_retry), and
non-TLV compat fields into a single HashMap
- in_flight_monitor_updates: Convert legacy TLV 10 (keyed by OutPoint)
to TLV 17 format (keyed by ChannelId)
- pending_events: Apply events_override (TLV 8) if present

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
second-pass: broader security terminology
AI analysis · Low 28/100

This commit is an internal code cleanup in the Lightning Dev Kit's channel manager. It moves the handling of old data formats (legacy TLV fields) from a later initialization stage into the deserialization stage, so the data structure is normalized earlier. There is no direct evidence this fixes an active security vulnerability; it appears to be a maintainability and correctness refactor to prevent inconsistencies when loading older persisted data.

AI review queuedExtract second stage of ChannelManager::read into from_channel_manager_databy Joost Jager · f08f4b4f · Feb 2, 2026 · 1 fileMessage 83 · StrongInformational 15Details
Commit message · Joost Jager

Extract second stage of ChannelManager::read into from_channel_manager_data

Move the validation and reconstruction logic (stage 2) from the
ReadableArgs::read implementation into a new pub(super) constructor
`from_channel_manager_data`. This separates the pure deserialization
from the complex reconstruction logic, making the code more modular
and easier to test.

The read function now:
1. Deserializes into ChannelManagerData (stage 1)
2. Calls from_channel_manager_data for validation/reconstruction (stage 2)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 15/100

This commit is a pure code refactoring: it moves an existing block of logic from one place inside a function into a newly created helper function, without changing what the logic actually does. There is no security-relevant behavior change visible in the diff.

AI review queuedUnwrap TLV fields with initialized defaults in ChannelManagerDataby Joost Jager · fe6fd648 · Feb 2, 2026 · 1 fileMessage 73 · AdequateInformational 18Details
Commit message · Joost Jager

Unwrap TLV fields with initialized defaults in ChannelManagerData

For TLV fields that are initialized with Some(...) before reading and
thus always have a value after deserialization, remove the Option
wrapper from ChannelManagerData and unwrap when constructing it.

This applies to pending_claiming_payments and
monitor_update_blocked_actions_per_peer.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 18/100

This is a small internal cleanup in the Lightning Dev Kit's Rust code. It removes unnecessary 'Option' wrappers from two data fields that are always set during deserialization, replacing later `.unwrap()` calls with direct use. The change does not introduce a new security vulnerability; it is a refactoring that makes the code clearer and slightly reduces panic risk by moving the unwrapping to a point where the value is guaranteed to exist.

AI review queuedSplit ChannelManager::read into two stagesby Joost Jager · 3deecd4a · Feb 2, 2026 · 1 fileMessage 68 · AdequateInformational 12Details
Commit message · Joost Jager

Split ChannelManager::read into two stages

Introduce ChannelManagerData<SP> as an intermediate DTO that holds all
deserialized data from a ChannelManager before validation. This splits
the read implementation into:

1. Stage 1: Pure deserialization into ChannelManagerData
2. Stage 2: Validation and reconstruction using the DTO

The existing validation and reconstruction logic remains unchanged;
only the deserialization portion was extracted into the DTO's
ReadableArgs implementation.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 12/100

This commit is a pure internal code reorganization. It splits the loading of a Lightning node's ChannelManager into two steps: first reading raw data into a temporary data holder, then validating and building the actual ChannelManager. No security behavior appears to change; it is a refactoring to make the code easier to maintain and test.

Security candidateIntroduce custom TLVs in `pay_for_bolt11_invoice`by shaavan · 6b20feee · Jan 30, 2026 · 6 filesMessage 73 · AdequateInformational 23Details
Commit message · shaavan

Introduce custom TLVs in `pay_for_bolt11_invoice`

Custom TLVs let the payer attach arbitrary data to the onion packet,
enabling everything from richer metadata to custom authentication on
the payee's side.

Until now, this flexibility existed only through `send_payment`. The
simpler `pay_for_bolt11_invoice` API offered no way to pass custom
TLVs, limiting its usefulness in flows that rely on additional context.

This commit adds custom TLV support to `pay_for_bolt11_invoice`,
bringing it to feature parity.

73/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Names security-relevant behavior explicitly
Why it was queued
access control
AI analysis · Informational 23/100

This commit is a routine API enhancement for the Lightning Dev Kit's rust-lightning library. It adds the ability for users to include custom data (called 'custom TLVs') when paying a BOLT11 invoice through the simpler `pay_for_bolt11_invoice` API, matching a capability already available in the more advanced `send_payment` API. The change mostly refactors how optional payment arguments are passed, grouping route settings, retry settings, and the new custom TLVs into a single `OptionalBolt11PaymentParams` struct. There is no direct evidence in the commit that this fixes a security vulnerability; it appears to be a feature addition for flexibility.

AI review queuedDrop Deref indirection for SignerProviderby Valentine Wallace · 9432adbc · Jan 30, 2026 · 9 filesMessage 68 · AdequateInformational 13Details
Commit message · Valentine Wallace

Drop Deref indirection for SignerProvider

Reduces generics and verbosity across the codebase, should provide equivalent
behavior.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 13/100

This commit is a straightforward internal code cleanup in the Lightning Dev Kit's Rust library. It removes an unnecessary layer of pointer-like indirection (the Deref trait) around the SignerProvider type used throughout channel and monitor code. The change simplifies type signatures and reduces boilerplate but does not alter what the code actually does or how it protects funds.

AI review queuedDrop Deref indirection for OutputSpenderby Valentine Wallace · 644ca0c6 · Jan 30, 2026 · 3 filesMessage 68 · AdequateInformational 15Details
Commit message · Valentine Wallace

Drop Deref indirection for OutputSpender

Reduces generics and verbosity across the codebase, should provide equivalent
behavior.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a routine Rust code cleanup change. It removes the requirement that an OutputSpender must be wrapped in a Deref pointer (like Arc or reference), and instead makes OutputSpender work directly through a blanket implementation. The commit message says it reduces generics and verbosity while keeping the same behavior. There is no security fix here.

AI review queuedDrop Deref indirection for Loggerby Valentine Wallace · ac8074e5 · Jan 30, 2026 · 30 filesMessage 68 · AdequateInformational 18Details
Commit message · Valentine Wallace

Drop Deref indirection for Logger

Reduces generics and verbosity across the codebase, should provide equivalent
behavior.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 18/100

This is a large but straightforward internal refactoring of the Rust Lightning code. It removes an extra layer of pointer indirection (the Deref trait) from how the Logger type is passed around, replacing it with direct Logger trait bounds. The commit message says the goal is to reduce generics and verbosity while keeping the same behavior. There is no change to cryptographic logic, network protocol handling, or security-sensitive operations.

Security candidateDrop Deref indirection for EntropySourceby Valentine Wallace · 32e6e100 · Jan 30, 2026 · 31 filesMessage 68 · AdequateInformational 19Details
Commit message · Valentine Wallace

Drop Deref indirection for EntropySource

Reduces generics and verbosity across the codebase, should provide equivalent
behavior.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
entropy or randomnesscryptography-sensitive pathsigning or wallet path
AI analysis · Informational 19/100

This commit is a large internal cleanup in the rust-lightning codebase. It removes an extra layer of pointer indirection (the Deref trait) from how randomness sources are passed around, replacing it with a direct EntropySource trait bound. The change simplifies type signatures and reduces boilerplate but does not appear to fix a security bug or introduce a new vulnerability. A blanket implementation of EntropySource for any type that dereferences to an EntropySource is added to preserve backward compatibility with existing callers.

Security candidateDrop Deref indirection for NodeSignerby Valentine Wallace · fb2759e8 · Jan 30, 2026 · 17 filesMessage 68 · AdequateInformational 18Details
Commit message · Valentine Wallace

Drop Deref indirection for NodeSigner

Reduces generics and verbosity across the codebase, should provide equivalent
behavior.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 18/100

This commit is a code cleanup change in the Lightning Dev Kit Rust library. It removes an extra layer of pointer-like wrapping (called Deref indirection) around the NodeSigner type, which is responsible for node-level cryptographic operations like signing messages and deriving keys. The change simplifies type signatures across many files but does not alter what the code actually does or fix any security bug. The commit message explicitly states the goal is to reduce generics and verbosity while providing equivalent behavior.

AI review queuedDrop Deref indirection for BroadcasterInterfaceby Valentine Wallace · aa9feace · Jan 30, 2026 · 14 filesMessage 68 · AdequateInformational 18Details
Commit message · Valentine Wallace

Drop Deref indirection for BroadcasterInterface

Reduces generics and verbosity across the codebase, should
provide equivalent behavior.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100

This commit is a large but straightforward internal code cleanup in the Lightning Dev Kit Rust library. It removes an extra layer of pointer-like generic wrapping (the `Deref` indirection) around the transaction-broadcasting interface and instead uses the trait directly. The commit message says the goal is to reduce generics and verbosity while keeping the same behavior. There is no indication this fixes a security bug or changes runtime behavior in a way that introduces a vulnerability.

Lower-priorityExtend full_stack fuzz test to cover splicingby Wilmer Paulino · b52b0692 · Jan 30, 2026 · 1 fileMessage 78 · AdequateInformational 15Details
Commit message · Wilmer Paulino

Extend full_stack fuzz test to cover splicing

This includes a new seed that covers the splice flow to completion
(exchanging `splice_locked` and promoting the `FundingScope`).

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
fuzzing or regression evidence
AI analysis · Informational 15/100

This commit is a routine test improvement. It extends an existing fuzzing harness to exercise the new Lightning channel splicing feature, adding test-only code and a deterministic seed that walks through a splice-in flow. There is no change to production code, no bug fix, and no security patch.

Security candidateSupport funding_transaction_signed for unfunded dual-funded channelsby Wilmer Paulino · be67c67f · Jan 29, 2026 · 2 filesMessage 85 · StrongLow 32Details
Commit message · Wilmer Paulino

Support funding_transaction_signed for unfunded dual-funded channels

Now that we require users to first call
`ChannelManager::funding_transaction_signed` before releasing any
signatures, it's possible that it is called before we receive the
initial commitment signed from our counterparty, which would transition
the channel to funded. Because of this, we need to support the API call
while the channel is still in the unfunded phase.

Note that this commit is mostly a code move of
`FundedChannel::funding_transaction_signed` to
`Channel::funding_transaction_signed` that doesn't alter the signing
logic.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
signing boundary
AI analysis · Low 32/100

This commit moves the handling of funding-transaction signatures so it can be called earlier, while a dual-funded Lightning channel is still unfunded. Previously the API required the channel to already be in a funded state, which could fail if a user signed before the counterparty's first commitment arrived. The change is described by the authors as mostly a code move that does not alter the actual signing logic.

Security candidateRework ChannelManager::funding_transaction_signedby Wilmer Paulino · 83b2d3ec · Jan 29, 2026 · 6 filesMessage 58 · ThinLow 33Details
Commit message · Wilmer Paulino

Rework ChannelManager::funding_transaction_signed

Previously, we'd emit a FundingTransactionReadyForSigning event once the
initial commitment_signed is exchanged for a splicing/dual-funding
attempt and require users to call back with their signed inputs using
ChannelManager::funding_transaction_signed. While this approach worked
in practice, it prevents us from abandoning a splice if we cannot or no
longer wish to sign as the splice has already been committed to by this
point.

This commit reworks the API such that this is now possible. After
exchanging tx_complete, we will no longer immediately send our initial
commitment_signed. We will now emit the
FundingTransactionReadyForSigning event and wait for the user to call
back before releasing both our initial commitment_signed and our
tx_signatures. As a result, the event is now persisted, as there is only
one possible path in which it is generated. Note that we continue to
only emit the event if a local contribution to negotiated transaction
was made.

Future work will expose a cancellation API such that we can abandon
splice attempts safely (we can just force close the channel with
dual-funding).

58/100 · ThinMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context
Why it was queued
signing boundary
AI analysis · Low 33/100

This commit reorders the splicing/dual-funding handshake in LDK so that the node does not send its initial commitment signature until after the user has had a chance to sign the funding transaction. Previously, the commitment was sent first, which locked the node into the splice even if the user could not or did not want to sign. The change also makes the 'ready to sign' event persistent across restarts and adds a forward-compatibility note that downgrading while a splice is pending is not supported with async monitor updates. It is a protocol-flow hardening change, not a fix for an active exploit.

AI review queuedFix race condition in async `UtxoFuture` resolutionby Elias Rohrer · 114f6b56 · Jan 29, 2026 · 1 fileMessage 73 · AdequateLow 43Details
Commit message · Elias Rohrer

Fix race condition in async `UtxoFuture` resolution

Previously, we refactored the `GossipVerifier` to not require holding a
circular reference. As part of this, we moved to a model where the
`UtxoFuture`s are now polled by the background processor which checks
for completion through `get_and_clear_pending_msg_events`.

However, as part of this refactor we introduced race-condition: as we
only held `Weak` references in `PendingChecksContext` and the
`UtxoFuture` was directly dropped by the `GossipVerifier` after calling
`resolve`, the actual data was dropped with the future and gone when the
background processor attempted to retrieve and apply it via
`check_resolved_futures`.

Here, we fix this issue by simply holding on to the `state` `Arc`s in a
separate `pending_states` `Vec` that is only pruned in
`check_resolved_futures`, ensuring any completed results are collected
first.

Signed-off-by: Elias Rohrer <dev@tnull.de>

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
second-pass: broader security terminology
AI analysis · Low 43/100

This commit fixes a race condition in how the Lightning Dev Kit processes background checks on channel announcements (UTXO lookups). Previously, the result of a completed check could be thrown away before another part of the system could collect it, meaning valid gossip messages might be silently lost and not applied to the network graph. The fix keeps the result alive until it is explicitly collected.