Skip to content

Refuse to splice a channel without option_unified_sigs - #22

Merged
kwsantiago merged 3 commits into
blake2b-unifiedfrom
blake2b-unified-splice
Oct 1, 2026
Merged

kwsantiago merged 3 commits into
blake2b-unifiedfrom
blake2b-unified-splice

Conversation

@kwsantiago

Copy link
Copy Markdown

A splice co-signs the previous funding output with the channel's hash type. On a channel without option_unified_sigs, such as any opened with v26.06.7-blake2b.1 to .3, that carries it into a new funding output that is also valid for a node that has not upgraded.

  • splice_init refuses such a channel.
  • channeld refuses a peer's splice on one with a warning, as it does for an out-of-range feerate.
  • --dev-splice-without-unified-sigs skips our own check so the peer's refusal can be tested.
  • doc/blake2b-upgrade.md §4 said the opt-in was added "whenever both peers support it". New channels already require it from both sides; the text now says so, and tells operators to close and reopen older channels.

Tests in tests/test_unified_robustness.py:

  • test_new_channel_requires_unified_sigs: a node without option_unified_sigs can neither open a channel to an upgraded node nor accept one, over v1 and v2 opens.
  • test_no_splice_without_unified_sigs: fails without this change.

Changelog-None

@kwsantiago
kwsantiago merged commit f82f98a into blake2b-unified Oct 1, 2026
96 of 104 checks passed
@kwsantiago
kwsantiago deleted the blake2b-unified-splice branch October 1, 2026 02:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant