Skip to content

smite: add is_standard_shutdown_script helper - #186

Open
ekzyis wants to merge 1 commit into
lnfuzz:masterfrom
ekzyis:is-standard-shutdown-script
Open

smite: add is_standard_shutdown_script helper#186
ekzyis wants to merge 1 commit into
lnfuzz:masterfrom
ekzyis:is-standard-shutdown-script

Conversation

@ekzyis

@ekzyis ekzyis commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

From the commit message:

BOLT-02 specifies sender requirements for shutdown scripts. They must be
witness v0 (P2WPKH, P2WSH) or following features must be negotiated:

  • option_shutdown_anysegwit: witness v1-v16 with a 2..=40 byte program
  • option_simple_close: OP_RETURN with a single data push of 6..=80
    bytes

Legacy scripts (P2PKH, P2SH) may be accepted for backward compatibility.

This applies to the shutdown and closing_complete messages, and the
upfront_shutdown_script TLV in the open_channel, open_channel2,
accept_channel and accept_channel2 messages.

This commit adds a helper to catch targets that don't comply with the
spec.

As per the note I added to the code, I'm not sure if the fuzzer should also reject legacy scripts, since a target must not send them. update: decided to reject them, see discussion

I haven't wired this into existing code or #163 yet, but I thought the introduction of the helper might be worthwile to review itself, especially considering the question wrt legacy scripts.

@ekzyis
ekzyis force-pushed the is-standard-shutdown-script branch from f33051b to 22217d9 Compare August 4, 2026 11:07

@NishantBansal2003 NishantBansal2003 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! I was about to add this as a follow-up to #185, but it looks like I don’t have to now

Comment thread smite/src/bolt/shutdown.rs Outdated
Comment on lines +57 to +65
/// Feature bits that widen the set of standard `shutdown` scriptpubkeys.
#[derive(Debug, Clone, Copy, Default, PartialEq, Eq)]
pub struct ShutdownScriptFeatures {
/// Additionally permits witness program versions 1..=16 with a 2..=40 byte
/// program.
pub option_shutdown_anysegwit: bool,
/// Additionally permits a single-push `OP_RETURN` script.
pub option_simple_close: bool,
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this can be removed/simplified once #192 gets merged, so we can just use just use: negotiated_features.supports_feature(Features::OPTION_SHUTDOWN_ANYSEGWIT) or negotiated_features.supports_feature(Features::OPTION_SIMPLE_CLOSE)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds good, I will review #192 and then rebase this PR after merge

Comment thread smite/src/bolt/shutdown.rs Outdated

/// Returns `true` if `spk` is a BOLT 2 `option_simple_close` `OP_RETURN`
/// script: `OP_RETURN` followed by a single data push of 6 to 80 bytes.
fn is_simple_close_op_return(spk: &[u8]) -> bool {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, nice, thanks! Done in 220b1bf. I noticed I need to use script.instructions_minimal() instead of script.instructions() to catch non-minimal pushes, see comment + test.

LDK intentionally accepts non-minimal pushes because of Postel's law, see here.

Comment thread smite/src/bolt/shutdown.rs Outdated
@ekzyis
ekzyis force-pushed the is-standard-shutdown-script branch from 22217d9 to 220b1bf Compare August 9, 2026 12:30
Comment thread smite/src/bolt/shutdown.rs Outdated
BOLT-02 specifies sender requirements for shutdown scripts. They must be
witness v0 (P2WPKH, P2WSH) or following features must be negotiated:

* `option_shutdown_anysegwit`: witness v1-v16 with a 2..=40 byte program
* `option_simple_close`: `OP_RETURN` with a single minimal data push of
  6..=80 bytes

Receivers may accept legacy scripts (P2PKH, P2SH), but we reject them
since we're judging the sender's output.

This applies to the `shutdown` and `closing_complete` messages, and the
`upfront_shutdown_script` TLV in the `open_channel`, `open_channel2`,
`accept_channel` and `accept_channel2` messages.

This commit adds a helper to catch targets that don't comply with the
spec.
@ekzyis
ekzyis force-pushed the is-standard-shutdown-script branch from 220b1bf to 847c2f1 Compare August 9, 2026 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants