Add an opt-in check that prevents the sum of all account balances from exceeding the node's available local (outbound) channel balance. When enabled via the new accounts.check-channel-balance config option, the service rejects balance allocations that would over-provision the node: creating an account, an administrative credit, or an administrative balance increase now fails with ErrBalanceReservationExceeded if it would push the total allocated balance above the node's local channel balance. Note that the total channel balance may still decrease below the already allocated account balance. This can occur if the node operator decreases the total channel balance through non-account related activity. The check is a no-op by default to preserve the historical behaviour where the operator manages over-provisioning themselves (accounts can legitimately be created before channels are funded). Invoice-driven credits are unaffected, as they are backed by real inbound payments.
5.3 KiB
Release Notes
Lightning Terminal
Bug Fixes
-
Gate wallet-ready status on lnd's actual RPC readiness: Fixed a startup race where litd could report the LND sub-server as "Wallet Ready" before lnd's RPC interceptor had actually left its
WAITING_TO_STARTstate, so the very next call could still fail withrpc error: ... waiting to start. -
Don't mask account payment errors when request values are absent: When a streaming account payment (
SendPaymentV2/SendToRouteV2) fails and lnd returns a terminal error after the request values have already been cleaned up, lnd's underlying error is now passed through to the caller instead of being masked by a confusingno request values found for request: <id>error. -
Wait longer for lnd during the kvdb-to-SQL migration: The kvdb-to-SQL data migration polls lnd's
ListMacaroonIDsRPC, which only becomes available once lnd reaches its "RPC active" state. On nodes with a large channel/graph state, lnd can take well over a minute to get there after the wallet is unlocked, which exceeded the previous fixed 60-second poll budget and caused the migration (and therefore litd startup) to fail permanently, requiring a manual restart. The wait is now bounded by a configurable, generous timeout (--lndreadytimeout, defaulting to 10 minutes) instead of a fixed attempt count.
Functional Changes/Additions
-
Add accounts payments history subcommand: Added the
litcli accounts paymentssubcommand and corresponding gRPC endpointAccountPaymentsto retrieve the off-chain payment history of an account, supporting pagination (sorted in ascending lexicographical order of their payment hash) and counting of total payments. -
Auto-bake super macaroon on startup: Added config options
--bake-super-macaroon(choice:none,read-only,read-write) and--super-macaroon-pathto automatically bake a super macaroon on startup and keep its permissions in sync. When set toread-onlyorread-write, the daemon will automatically bake a super macaroon containing read-only or read-write permissions, respectively, for all active sub-servers on startup. If the macaroon already exists but has different permissions, it will be automatically regenerated. -
Add a configurable maximum account payment size: Addresses #583. Added an
accounts.max-payment-size-msatconfig option. When set to a non-zero value, the account interceptor rejects any single account payment (SendPaymentV2/SendToRouteV2) whose total amount, including fees, exceeds the configured cap, providing a guard rail against a compromised or misbehaving account macaroon draining its balance in one large payment. It defaults to 0 (no cap), preserving existing behaviour. This is a first step towards the finer-grained per-account spending controls tracked in the issue (e.g. per-interval spend limits). -
Optionally cap total account balances at the node's channel balance: Addresses #495. Added an opt-in
accounts.check-channel-balanceconfig option. When enabled, the accounts service rejects balance allocations (new accounts, administrative credits and administrative balance increases) that would push the sum of all account balances above the node's available local (outbound) channel balance, helping operators avoid over-provisioning custodial accounts beyond what the node can actually pay out. It defaults to off to preserve existing behaviour.
Technical and Architectural Updates
-
Report litd's own version for
litd -V: The-Vflag now prints litd's version instead of the integrated lnd version. -
Refactor privacy mapper to prevent 32-bit truncation and optimize allocations: Refactored the privacy mapper's random number generation to use
int64instead ofintto prevent architecture-dependent truncation on 32-bit runtimes. This represents a breaking change to theNewPrivacyMapperandCryptoRandIntnfunctions. The PR also introduced async.Poolfor*big.Intto optimize allocations.
RPC Updates
Integrated Binary Updates
LND
Loop
Pool
Faraday
Taproot Assets
Contributors (Alphabetical Order)
- 0xfandom
- bitromortac
- Cyberguru1
- Vandit Singh