lnd/lnwire/bounds.go
bitromortac 9113a53337 lnwire: add bounded introNode BlindedPath codec
Introduce the canonical lnwire.BlindedPath / BlindedPaths codec with a
sealed IntroductionNode sum-type covering both the BOLT 4 pubkey and
sciddir variants. The codec gates every variable-length subfield against
an io.LimitedReader. It fails closed on the encoder side so invalid
input never hits the wire.

This commit is a pure addition: no existing caller changes. Subsequent
commits migrate OnionMessagePayload and the bolt12 message structs to
consume the new codec.
2026-06-03 12:11:29 +02:00

35 lines
1.1 KiB
Go

package lnwire
import (
"math"
"github.com/btcsuite/btcd/btcec/v2"
)
// BOLT 4 blinded-path field bounds. Each constant matches the format ceiling
// imposed by the spec encoding (uint8 num_hops, uint16 enclen).
const (
// pubKeyLen aliases the upstream compressed-pubkey length for shorter
// usage in this package.
pubKeyLen = btcec.PubKeyBytesLenCompressed
// sciddirLen is the on-wire length of a sciddir introduction node
// (1-byte direction + 8-byte SCID).
sciddirLen = 9
// scidLen is the byte length of a short channel ID.
scidLen = 8
// maxBlindedPathHops bounds the number of hops a single blinded path
// may declare. The spec encodes num_hops as a uint8, so 255 is the
// format's absolute ceiling.
maxBlindedPathHops = math.MaxUint8
// maxEncryptedDataLen bounds the encrypted-data field in a single
// blinded hop. The spec encodes the length as a uint16.
maxEncryptedDataLen = math.MaxUint16
// minBlindedHopBytes is the on-wire footprint of the smallest possible
// blinded hop: BlindedNodeID(33) + enclen(2) + 0 enc_data.
minBlindedHopBytes = pubKeyLen + 2
)