CCF icon indicating copy to clipboard operation
CCF copied to clipboard

Add test of a node using a rolled-back cert

Open eddyashton opened this issue 5 months ago • 1 comments

Noted and mitigated around #7057.

A node updates the cert it will put into signatures and use for node-to-node channels on a local hook. That means it might be rolled back. There's a comment saying that's safe, because this cert is only modified when a node is added, so a rollback means the node is removed.

That's not true!

The cert is also updated on cert refresh. This could also be rolled back, and result in the node using a cert which has not been written to the ledger.

eddyashton avatar Jun 18 '25 15:06 eddyashton

I think this is a dupe of #3250, but good point about the refresh.

achamayou avatar Jun 19 '25 08:06 achamayou