A failed payout permanently burns a unique sub-link: allowance is consumed before pay_invoice and not restored on failure #5
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
In
api_lnurl_callbackthe sub-link is removed fromusescsvbefore any payment is attempted (views_lnurl.py:126-128), and theexceptbranch (views_lnurl.py:164-167) only deletes the hash-check mutex. A transientpay_invoicefailure (no route, liquidity, node restart) leaves the customer with an error and the link owner one use short with nothing withdrawn; the sub-link can never be retried. For ATM cash-ins this is a stranded customer at the machine with the voucher already spent on our side.Fix direction: reserve the use before paying (to keep the double-spend window closed) and release it on failure — restore the slot to
usescsvand decrementusedatomically — so a use is committed only on settlement. Same primitives as the race fix above (sandbox PR #11,release_withdraw_link_use); ship them together.Found during reforge run #1 (sandbox withdraw#2).