AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 60 Bitcoin

Merge PR 'Fail held HTLC failures when force-closing' (#5050)

Public commit record

What the developer wrote

Authored by Matt Corallo

81/100 · Strong
Merge PR 'Fail held HTLC failures when force-closing' (#5050)

from fail-back-htlc-fc into main

Reviewed-on: https://git.rust-bitcoin.org/lightningdevkit/rust-lightning/pulls/5050
Reviewed-by: Matt Corallo <matt@noreply.git.rust-bitcoin.org>
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit fixes a bug in the Lightning Dev Kit where a forwarded payment could get permanently stuck if a channel was force-closed at exactly the wrong moment. Normally, when the next node in a route rejects a payment, that rejection is held back briefly until the channel state is fully updated. If the channel was force-closed while that rejection was still held back, the rejection could be lost and the payment would never be failed backwards to the sender. The fix hands those held-back failures to the channel's on-chain monitor so they are released once the monitor is updated, preventing stuck payments.

Recommended action

Review and merge if not already merged; ensure downstream users upgrade to a release containing this fix, as the bug can leave forwarded payments unresolved after a force-close. No immediate emergency response is indicated because exploitation requires a specific timing/operational condition rather than an attacker-controlled protocol violation.

Security signals we found

01

Fixes a stuck-HTLC / payment resolution failure on force-close

02

Adds counterparty_failed_htlcs to ChannelForceClosed monitor update step

03

Drains monitor_pending_failures into the closing monitor update

04

Skips HTLCs still present in tracked counterparty commitments to avoid unsafe premature failure

05

Includes regression tests for multiple force-close triggers and restart scenarios

Risk score

Why this scored 60/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.