AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 30 Bitcoin

connectd: keep the subd fd until connectd has received it

Public commit record

What the developer wrote

Authored by dovgopoly

73/100 · Adequate
connectd: keep the subd fd until connectd has received it

On macOS, a socket passed over SCM_RIGHTS whose sender closes its copy before the receiver's recvmsg completes can arrive unable to read. lightningd closed its end of a new subd's connection right after queueing it for connectd, so openingd or channeld could start with a dead connection: openingd logged "Peer connection lost", and fundchannel failed or hung waiting for accept_channel.

connectd now replies to peer_connect_subd once it has the fd, and lightningd keeps its copy until the reply arrives.

Changelog-Fixed: macOS: fundchannel no longer fails or hangs with "Peer connection lost" when opening channels under load.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit fixes a macOS-specific bug where opening a Lightning channel could fail or hang with 'Peer connection lost'. The root cause was a race condition in how file descriptors (sockets) were passed between internal processes: the sender closed its copy too early, before the receiver had fully received it. The fix makes the sender wait for an acknowledgment before closing its copy. It is a reliability/availability fix, not an exploitable security vulnerability.

Recommended action

Treat as a normal bug fix. No security-specific action required beyond standard review and regression testing on macOS for channel open paths.

Security signals we found

01

Race condition in inter-process file descriptor passing (SCM_RIGHTS)

02

Availability impact: fundchannel failure/hang under load on macOS

03

No evidence of confidentiality or integrity compromise

04

Fix adds explicit acknowledgment before releasing fd reference

Risk score

Why this scored 30/100

Our methodology →
Potential impact 8/30
Exploitability 2/25
Stealth signal 3/15
Affected reach 5/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.