From 8366346601c4054007bdea1b7ae981d7780fefa3 Mon Sep 17 00:00:00 2001 From: Matt Morehouse Date: Fri, 25 Sep 2026 11:53:59 -0500 Subject: [PATCH 1/3] =?UTF-8?q?data/authors:=20add=20Niklas=20G=C3=B6gge?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- data/authors.yaml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/data/authors.yaml b/data/authors.yaml index c209426..6a50398 100644 --- a/data/authors.yaml +++ b/data/authors.yaml @@ -18,3 +18,8 @@ erick: name: Erick Cestari github: erickcestari url: https://erickcestari.dev + +niklas: + name: Niklas Gögge + github: dergoegge + url: https://dergoegge.de From 0405daba413cffe8fff3f572d2dcc1a11addab2f Mon Sep 17 00:00:00 2001 From: Matt Morehouse Date: Fri, 25 Sep 2026 12:02:13 -0500 Subject: [PATCH 2/3] layouts: add "race" bug type --- data/bugs.yaml | 2 +- layouts/_partials/validate-bugs.html | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/data/bugs.yaml b/data/bugs.yaml index 1cb7f40..3072acd 100644 --- a/data/bugs.yaml +++ b/data/bugs.yaml @@ -6,7 +6,7 @@ # target: lnd | cln | ldk | eclair | spec # status: fixed | reported | wontfix # impact: theft | grief | dos | crash | debug-assert | ub | uninit | -# liveness | spec +# liveness | spec | race # # `found_with` is how the bug was discovered. Optional. /projects/smite/ renders # the entries whose value is `smite`. diff --git a/layouts/_partials/validate-bugs.html b/layouts/_partials/validate-bugs.html index af784fa..d21ad93 100644 --- a/layouts/_partials/validate-bugs.html +++ b/layouts/_partials/validate-bugs.html @@ -7,7 +7,7 @@ */ -}} {{- $targets := slice "lnd" "cln" "ldk" "eclair" "spec" -}} {{- $statuses := slice "fixed" "reported" "wontfix" -}} -{{- $impacts := slice "theft" "grief" "dos" "crash" "debug-assert" "ub" "uninit" "liveness" "spec" -}} +{{- $impacts := slice "theft" "grief" "dos" "crash" "debug-assert" "ub" "uninit" "liveness" "spec" "race" -}} {{- $seen := slice -}} {{- range $i, $b := hugo.Data.bugs -}} {{- $at := printf "data/bugs.yaml entry %d (%s)" (add $i 1) (or $b.id "") -}} From f664d5b605f3c9b7497e7d0b1cd60613954b4489 Mon Sep 17 00:00:00 2001 From: Matt Morehouse Date: Fri, 25 Sep 2026 12:03:13 -0500 Subject: [PATCH 3/3] data/bugs: add two bugs found by Niklas --- data/bugs.yaml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/data/bugs.yaml b/data/bugs.yaml index 3072acd..61621c1 100644 --- a/data/bugs.yaml +++ b/data/bugs.yaml @@ -381,6 +381,26 @@ reported: 2026-09-24 upstream: https://github.com/ElementsProject/lightning/issues/9570 +- id: lnd-channel-open-race-latent-nil-deref + title: "Channel-open race with latent nil dereference" + found_with: smite + target: lnd + status: reported + impact: race + credit: [niklas, matt] + reported: 2026-09-24 + upstream: https://github.com/lightningnetwork/lnd/issues/11259 + +- id: cln-channeld-large-htlc-abort + title: "channeld aborts on large `update_add_htlc` amount" + found_with: smite + target: cln + status: reported + impact: crash + credit: [niklas, matt] + reported: 2026-09-25 + upstream: https://github.com/ElementsProject/lightning/issues/9576 + - id: eclair-splice-init-overdraw title: "Failure to reject `splice_init` that overdraws the sender's balance" found_with: smite