@@ -1353,12 +1353,27 @@ pub fn create_payment_onion<T: secp256k1::Signing>(
13531353 keysend_preimage : & Option < PaymentPreimage > , invoice_request : Option < & InvoiceRequest > ,
13541354 prng_seed : [ u8 ; 32 ] ,
13551355) -> Result < ( msgs:: OnionPacket , u64 , u32 ) , APIError > {
1356- let mut trampoline_payloads = vec ! [ ] ;
1356+ create_payment_onion_internal ( secp_ctx, path, session_priv, total_msat, recipient_onion,
1357+ cur_block_height, payment_hash, keysend_preimage, invoice_request,
1358+ prng_seed, None , None , None )
1359+ }
1360+
1361+ /// Build a payment onion, returning the first hop msat and cltv values as well.
1362+ /// `cur_block_height` should be set to the best known block height + 1.
1363+ pub ( crate ) fn create_payment_onion_internal < T : secp256k1:: Signing > (
1364+ secp_ctx : & Secp256k1 < T > , path : & Path , session_priv : & SecretKey , total_msat : u64 ,
1365+ recipient_onion : & RecipientOnionFields , cur_block_height : u32 , payment_hash : & PaymentHash ,
1366+ keysend_preimage : & Option < PaymentPreimage > , invoice_request : Option < & InvoiceRequest > ,
1367+ prng_seed : [ u8 ; 32 ] , secondary_payment_secret : Option < PaymentSecret > ,
1368+ secondary_session_priv : Option < SecretKey > , secondary_prng_seed : Option < [ u8 ; 32 ] >
1369+ ) -> Result < ( msgs:: OnionPacket , u64 , u32 ) , APIError > {
13571370 let mut outer_total_msat = total_msat;
13581371 let mut outer_starting_htlc_offset = cur_block_height;
13591372 let mut outer_session_priv_override = None ;
1373+ let mut trampoline_packet_option = None ;
13601374
13611375 if !path. trampoline_hops . is_empty ( ) {
1376+ let trampoline_payloads;
13621377 ( trampoline_payloads, outer_total_msat, outer_starting_htlc_offset) =
13631378 build_trampoline_onion_payloads (
13641379 path,
@@ -1367,18 +1382,7 @@ pub fn create_payment_onion<T: secp256k1::Signing>(
13671382 cur_block_height,
13681383 keysend_preimage,
13691384 ) ?;
1370- }
13711385
1372- let ( mut onion_payloads, htlc_msat, htlc_cltv) = build_onion_payloads (
1373- & path,
1374- total_msat,
1375- recipient_onion,
1376- cur_block_height,
1377- keysend_preimage,
1378- invoice_request,
1379- ) ?;
1380-
1381- if !path. trampoline_hops . is_empty ( ) {
13821386 let onion_keys =
13831387 construct_trampoline_onion_keys ( & secp_ctx, & path, & session_priv) . map_err ( |_| {
13841388 APIError :: InvalidRoute {
@@ -1396,26 +1400,42 @@ pub fn create_payment_onion<T: secp256k1::Signing>(
13961400 err : "Route size too large considering onion data" . to_owned ( ) ,
13971401 } ) ?;
13981402
1403+ trampoline_packet_option = Some ( trampoline_packet) ;
1404+ }
1405+
1406+ let ( mut onion_payloads, htlc_msat, htlc_cltv) = build_onion_payloads (
1407+ & path,
1408+ outer_total_msat,
1409+ recipient_onion,
1410+ outer_starting_htlc_offset,
1411+ keysend_preimage,
1412+ invoice_request,
1413+ ) ?;
1414+
1415+ if !path. trampoline_hops . is_empty ( ) {
13991416 let last_payload = onion_payloads. pop ( ) . ok_or ( APIError :: InvalidRoute {
14001417 err : "Non-Trampoline path needs at least one hop" . to_owned ( ) ,
14011418 } ) ?;
14021419
14031420 match last_payload {
14041421 OutboundOnionPayload :: Receive { payment_data, .. } => {
1422+ let fee_delta = path. hops . last ( ) . map_or ( 0 , |h| h. fee_msat ) ;
1423+ let cltv_delta = path. hops . last ( ) . map_or ( 0 , |h| h. cltv_expiry_delta ) ;
14051424 let multipath_trampoline_data = payment_data. map ( |d| {
1406- let trampoline_payment_secret =
1407- Sha256 :: hash ( & d. payment_secret . 0 ) . to_byte_array ( ) ;
1408- let total_msat = d. total_msat + path. hops . last ( ) . map_or ( 0 , |h| h. fee_msat ) ;
1425+ let trampoline_payment_secret = secondary_payment_secret. unwrap_or_else ( || {
1426+ PaymentSecret ( Sha256 :: hash ( & d. payment_secret . 0 ) . to_byte_array ( ) )
1427+ } ) ;
1428+ let total_msat = fee_delta;
14091429 FinalOnionHopData {
1410- payment_secret : PaymentSecret ( trampoline_payment_secret) ,
1430+ payment_secret : trampoline_payment_secret,
14111431 total_msat,
14121432 }
14131433 } ) ;
14141434 onion_payloads. push ( OutboundOnionPayload :: TrampolineEntrypoint {
1415- amt_to_forward : outer_total_msat ,
1416- outgoing_cltv_value : outer_starting_htlc_offset,
1435+ amt_to_forward : fee_delta ,
1436+ outgoing_cltv_value : outer_starting_htlc_offset + cltv_delta ,
14171437 multipath_trampoline_data,
1418- trampoline_packet,
1438+ trampoline_packet : trampoline_packet_option . unwrap ( ) ,
14191439 } ) ;
14201440 } ,
14211441 _ => {
@@ -1426,16 +1446,18 @@ pub fn create_payment_onion<T: secp256k1::Signing>(
14261446 } ,
14271447 } ;
14281448
1429- let session_priv_hash = Sha256 :: hash ( & session_priv. secret_bytes ( ) ) . to_byte_array ( ) ;
1430- outer_session_priv_override =
1431- Some ( SecretKey :: from_slice ( & session_priv_hash[ ..] ) . expect ( "You broke SHA-256!" ) ) ;
1449+ outer_session_priv_override = Some ( secondary_session_priv. unwrap_or_else ( || {
1450+ let session_priv_hash = Sha256 :: hash ( & session_priv. secret_bytes ( ) ) . to_byte_array ( ) ;
1451+ SecretKey :: from_slice ( & session_priv_hash[ ..] ) . expect ( "You broke SHA-256!" )
1452+ } ) ) ;
14321453 }
14331454
14341455 let outer_session_priv = outer_session_priv_override. as_ref ( ) . unwrap_or ( session_priv) ;
14351456 let onion_keys = construct_onion_keys ( & secp_ctx, & path, outer_session_priv) . map_err ( |_| {
14361457 APIError :: InvalidRoute { err : "Pubkey along hop was maliciously selected" . to_owned ( ) }
14371458 } ) ?;
1438- let onion_packet = construct_onion_packet ( onion_payloads, onion_keys, prng_seed, payment_hash)
1459+ let outer_onion_prng_seed = secondary_prng_seed. unwrap_or ( prng_seed) ;
1460+ let onion_packet = construct_onion_packet ( onion_payloads, onion_keys, outer_onion_prng_seed, payment_hash)
14391461 . map_err ( |_| APIError :: InvalidRoute {
14401462 err : "Route size too large considering onion data" . to_owned ( ) ,
14411463 } ) ?;
0 commit comments