BOLT #2: * * A receiving node: * - MUST ignore `my_current_per_commitment_point`, but MAY require it to be * a valid point. * - if `next_revocation_number` is greater than expected above, AND * `your_last_per_commitment_secret` is correct for that * `next_revocation_number` minus 1: * - MUST NOT broadcast its commitment transaction. * - SHOULD send an `error` to
| 5599 | * - SHOULD send an `error` to request the peer to fail the channel. |
| 5600 | */ |
| 5601 | static void check_future_dataloss_fields(struct peer *peer, |
| 5602 | u64 next_revocation_number, |
| 5603 | const struct secret *last_local_per_commit_secret) |
| 5604 | { |
| 5605 | const u8 *msg; |
| 5606 | bool correct; |
| 5607 | |
| 5608 | assert(next_revocation_number > peer->next_index[LOCAL] - 1); |
| 5609 | |
| 5610 | if (next_revocation_number - 1 >= (1ULL << SHACHAIN_BITS)) { |
| 5611 | peer_failed_err(peer->pps, |
| 5612 | &peer->channel_id, |
| 5613 | "Invalid next_revocation_number value"); |
| 5614 | } |
| 5615 | |
| 5616 | msg = towire_hsmd_check_future_secret(NULL, |
| 5617 | next_revocation_number - 1, |
| 5618 | last_local_per_commit_secret); |
| 5619 | msg = hsm_req(tmpctx, take(msg)); |
| 5620 | if (!fromwire_hsmd_check_future_secret_reply(msg, &correct)) |
| 5621 | status_failed(STATUS_FAIL_HSM_IO, |
| 5622 | "Bad hsm_check_future_secret_reply: %s", |
| 5623 | tal_hex(tmpctx, msg)); |
| 5624 | |
| 5625 | if (!correct) |
| 5626 | peer_failed_err(peer->pps, |
| 5627 | &peer->channel_id, |
| 5628 | "bad future last_local_per_commit_secret: %"PRIu64 |
| 5629 | " vs %"PRIu64, |
| 5630 | next_revocation_number, |
| 5631 | peer->next_index[LOCAL] - 1); |
| 5632 | |
| 5633 | /* Oh shit, they really are from the future! */ |
| 5634 | peer_billboard(true, "They have future commitment number %"PRIu64 |
| 5635 | " vs our %"PRIu64". We must wait for them to close!", |
| 5636 | next_revocation_number, |
| 5637 | peer->next_index[LOCAL] - 1); |
| 5638 | |
| 5639 | /* BOLT #2: |
| 5640 | * - MUST NOT broadcast its commitment transaction. |
| 5641 | * - SHOULD send an `error` to request the peer to fail the channel. |
| 5642 | */ |
| 5643 | wire_sync_write(MASTER_FD, |
| 5644 | take(towire_channeld_fail_fallen_behind(NULL))); |
| 5645 | |
| 5646 | sleep(1); |
| 5647 | /* We have to send them an error to trigger dropping to chain. */ |
| 5648 | peer_failed_err(peer->pps, &peer->channel_id, |
| 5649 | "Awaiting unilateral close"); |
| 5650 | } |
| 5651 | |
| 5652 | /* BOLT #2: |
| 5653 | * |
no test coverage detected