AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Bitcoin

Merge PR 'Credit remote HTLC fulfills on remote HTLC adds' (#5043)

Public commit record

What the developer wrote

Authored by Matt Corallo

81/100 · Strong
Merge PR 'Credit remote HTLC fulfills on remote HTLC adds' (#5043)

from 2026-09-credit-htlc-fulfills into main

Reviewed-on: https://git.rust-bitcoin.org/lightningdevkit/rust-lightning/pulls/5043
Reviewed-by: Matt Corallo <matt@noreply.git.rust-bitcoin.org>
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit fixes how Lightning channels account for money that is about to be freed up when a payment succeeds or fails. Previously, the code could incorrectly let a node spend funds that were not yet actually available, or conversely block legitimate spending. The change makes the balance projection aware of whose turn it is in the commitment dance, so that incoming HTLC fulfillments are credited to the peer's available balance only when appropriate. New tests verify both the bug scenarios and the corrected behavior.

Recommended action

Review the new projection logic against the BOLT 2 commitment-state machine to ensure no edge cases are missed; run the new unit tests and fuzzing around HTLC add/fee validation; consider whether any existing channels in production could have been driven into an inconsistent state by the prior behavior.

Security signals we found

01

Channel balance/liquidity accounting change

02

HTLC fulfillment credit timing change

03

Prevention of premature spending of unacknowledged HTLC removals

04

New test cases for peer-update affordability and own-update holding-cell behavior

05

Refactor of next-commitment projection from boolean flag to explicit commitment-view enum

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.