• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

lightningnetwork / lnd / 23682929266

28 Mar 2026 10:06AM UTC coverage: 52.276% (-9.9%) from 62.223%
23682929266

Pull #10684

github

web-flow
Merge 3e33be4e8 into f297c4782
Pull Request #10684: sqldb: add network-mismatch safeguard for native-SQL backends

0 of 8 new or added lines in 1 file covered. (0.0%)

31019 existing lines in 474 files now uncovered.

102028 of 195171 relevant lines covered (52.28%)

2.17 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

55.44
/zpay32/encode.go
1
package zpay32
2

3
import (
4
        "bytes"
5
        "encoding/binary"
6
        "fmt"
7

8
        "github.com/btcsuite/btcd/btcutil"
9
        "github.com/btcsuite/btcd/btcutil/bech32"
10
        "github.com/btcsuite/btcd/chaincfg"
11
        "github.com/btcsuite/btcd/chaincfg/chainhash"
12
        "github.com/lightningnetwork/lnd/fn/v2"
13
        "github.com/lightningnetwork/lnd/lnwire"
14
)
15

16
// Encode takes the given MessageSigner and returns a string encoding this
17
// invoice signed by the node key of the signer.
18
func (invoice *Invoice) Encode(signer MessageSigner) (string, error) {
4✔
19
        // First check that this invoice is valid before starting the encoding.
4✔
20
        if err := validateInvoice(invoice); err != nil {
4✔
UNCOV
21
                return "", err
×
UNCOV
22
        }
×
23

24
        // The buffer will encoded the invoice data using 5-bit groups (base32).
25
        var bufferBase32 bytes.Buffer
4✔
26

4✔
27
        // The timestamp will be encoded using 35 bits, in base32.
4✔
28
        timestampBase32 := uint64ToBase32(uint64(invoice.Timestamp.Unix()))
4✔
29

4✔
30
        // The timestamp must be exactly 35 bits, which means 7 groups. If it
4✔
31
        // can fit into fewer groups we add leading zero groups, if it is too
4✔
32
        // big we fail early, as there is not possible to encode it.
4✔
33
        if len(timestampBase32) > timestampBase32Len {
4✔
34
                return "", fmt.Errorf("timestamp too big: %d",
×
35
                        invoice.Timestamp.Unix())
×
36
        }
×
37

38
        // Add zero bytes to the first timestampBase32Len-len(timestampBase32)
39
        // groups, then add the non-zero groups.
40
        zeroes := make([]byte, timestampBase32Len-len(timestampBase32))
4✔
41
        _, err := bufferBase32.Write(zeroes)
4✔
42
        if err != nil {
4✔
43
                return "", fmt.Errorf("unable to write to buffer: %w", err)
×
44
        }
×
45
        _, err = bufferBase32.Write(timestampBase32)
4✔
46
        if err != nil {
4✔
47
                return "", fmt.Errorf("unable to write to buffer: %w", err)
×
48
        }
×
49

50
        // We now write the tagged fields to the buffer, which will fill the
51
        // rest of the data part before the signature.
52
        if err := writeTaggedFields(&bufferBase32, invoice); err != nil {
4✔
53
                return "", err
×
54
        }
×
55

56
        // The human-readable part (hrp) is "ln" + net hrp + optional amount,
57
        // except for signet where we add an additional "s" to differentiate it
58
        // from the older testnet3 (Core devs decided to use the same hrp for
59
        // signet as for testnet3 which is not optimal for LN). See
60
        // https://github.com/lightningnetwork/lightning-rfc/pull/844 for more
61
        // information.
62
        hrp := "ln" + invoice.Net.Bech32HRPSegwit
4✔
63
        if invoice.Net.Name == chaincfg.SigNetParams.Name {
4✔
UNCOV
64
                hrp = "lntbs"
×
UNCOV
65
        }
×
66
        if invoice.MilliSat != nil {
8✔
67
                // Encode the amount using the fewest possible characters.
4✔
68
                am, err := encodeAmount(*invoice.MilliSat)
4✔
69
                if err != nil {
4✔
70
                        return "", err
×
71
                }
×
72
                hrp += am
4✔
73
        }
74

75
        // The signature is over the single SHA-256 hash of the hrp + the
76
        // tagged fields encoded in base256.
77
        taggedFieldsBytes, err := bech32.ConvertBits(bufferBase32.Bytes(), 5, 8, true)
4✔
78
        if err != nil {
4✔
79
                return "", err
×
80
        }
×
81

82
        toSign := append([]byte(hrp), taggedFieldsBytes...)
4✔
83

4✔
84
        // We use compact signature format, and also encoded the recovery ID
4✔
85
        // such that a reader of the invoice can recover our pubkey from the
4✔
86
        // signature.
4✔
87
        sign, err := signer.SignCompact(toSign)
4✔
88
        if err != nil {
4✔
89
                return "", err
×
90
        }
×
91

92
        // From the header byte we can extract the recovery ID, and the last 64
93
        // bytes encode the signature.
94
        recoveryID := sign[0] - 27 - 4
4✔
95
        sig, err := lnwire.NewSigFromWireECDSA(sign[1:])
4✔
96
        if err != nil {
4✔
97
                return "", err
×
98
        }
×
99

100
        // If the pubkey field was explicitly set, it must be set to the pubkey
101
        // used to create the signature.
102
        if invoice.Destination != nil {
4✔
UNCOV
103
                signature, err := sig.ToSignature()
×
UNCOV
104
                if err != nil {
×
105
                        return "", fmt.Errorf("unable to deserialize "+
×
106
                                "signature: %v", err)
×
107
                }
×
108

UNCOV
109
                hash := chainhash.HashB(toSign)
×
UNCOV
110
                valid := signature.Verify(hash, invoice.Destination)
×
UNCOV
111
                if !valid {
×
UNCOV
112
                        return "", fmt.Errorf("signature does not match " +
×
UNCOV
113
                                "provided pubkey")
×
UNCOV
114
                }
×
115
        }
116

117
        // Convert the signature to base32 before writing it to the buffer.
118
        signBase32, err := bech32.ConvertBits(
4✔
119
                append(sig.RawBytes(), recoveryID),
4✔
120
                8, 5, true,
4✔
121
        )
4✔
122
        if err != nil {
4✔
123
                return "", err
×
124
        }
×
125
        bufferBase32.Write(signBase32)
4✔
126

4✔
127
        // Now we can create the bech32 encoded string from the base32 buffer.
4✔
128
        b32, err := bech32.Encode(hrp, bufferBase32.Bytes())
4✔
129
        if err != nil {
4✔
130
                return "", err
×
131
        }
×
132

133
        // Before returning, check that the bech32 encoded string is not greater
134
        // than our largest supported invoice size.
135
        if len(b32) > maxInvoiceLength {
4✔
136
                return "", ErrInvoiceTooLarge
×
137
        }
×
138

139
        return b32, nil
4✔
140
}
141

142
// writeTaggedFields writes the non-nil tagged fields of the Invoice to the
143
// base32 buffer.
144
func writeTaggedFields(bufferBase32 *bytes.Buffer, invoice *Invoice) error {
4✔
145
        if invoice.PaymentHash != nil {
8✔
146
                err := writeBytes32(bufferBase32, fieldTypeP, *invoice.PaymentHash)
4✔
147
                if err != nil {
4✔
148
                        return err
×
149
                }
×
150
        }
151

152
        if invoice.Description != nil {
8✔
153
                base32, err := bech32.ConvertBits([]byte(*invoice.Description),
4✔
154
                        8, 5, true)
4✔
155
                if err != nil {
4✔
156
                        return err
×
157
                }
×
158
                err = writeTaggedField(bufferBase32, fieldTypeD, base32)
4✔
159
                if err != nil {
4✔
160
                        return err
×
161
                }
×
162
        }
163

164
        if invoice.DescriptionHash != nil {
4✔
UNCOV
165
                err := writeBytes32(
×
UNCOV
166
                        bufferBase32, fieldTypeH, *invoice.DescriptionHash,
×
UNCOV
167
                )
×
UNCOV
168
                if err != nil {
×
169
                        return err
×
170
                }
×
171
        }
172

173
        if invoice.Metadata != nil {
4✔
UNCOV
174
                base32, err := bech32.ConvertBits(invoice.Metadata, 8, 5, true)
×
UNCOV
175
                if err != nil {
×
176
                        return err
×
177
                }
×
UNCOV
178
                err = writeTaggedField(bufferBase32, fieldTypeM, base32)
×
UNCOV
179
                if err != nil {
×
180
                        return err
×
181
                }
×
182
        }
183

184
        if invoice.minFinalCLTVExpiry != nil {
8✔
185
                finalDelta := uint64ToBase32(*invoice.minFinalCLTVExpiry)
4✔
186
                err := writeTaggedField(bufferBase32, fieldTypeC, finalDelta)
4✔
187
                if err != nil {
4✔
188
                        return err
×
189
                }
×
190
        }
191

192
        if invoice.expiry != nil {
8✔
193
                seconds := invoice.expiry.Seconds()
4✔
194
                expiry := uint64ToBase32(uint64(seconds))
4✔
195
                err := writeTaggedField(bufferBase32, fieldTypeX, expiry)
4✔
196
                if err != nil {
4✔
197
                        return err
×
198
                }
×
199
        }
200

201
        if invoice.FallbackAddr != nil {
4✔
UNCOV
202
                var version byte
×
UNCOV
203
                switch addr := invoice.FallbackAddr.(type) {
×
UNCOV
204
                case *btcutil.AddressPubKeyHash:
×
UNCOV
205
                        version = fallbackVersionPubkeyHash
×
UNCOV
206
                case *btcutil.AddressScriptHash:
×
UNCOV
207
                        version = fallbackVersionScriptHash
×
UNCOV
208
                case *btcutil.AddressWitnessPubKeyHash:
×
UNCOV
209
                        version = addr.WitnessVersion()
×
UNCOV
210
                case *btcutil.AddressWitnessScriptHash:
×
UNCOV
211
                        version = addr.WitnessVersion()
×
UNCOV
212
                case *btcutil.AddressTaproot:
×
UNCOV
213
                        version = addr.WitnessVersion()
×
214
                default:
×
215
                        return fmt.Errorf("unknown fallback address type")
×
216
                }
UNCOV
217
                base32Addr, err := bech32.ConvertBits(
×
UNCOV
218
                        invoice.FallbackAddr.ScriptAddress(), 8, 5, true)
×
UNCOV
219
                if err != nil {
×
220
                        return err
×
221
                }
×
222

UNCOV
223
                err = writeTaggedField(bufferBase32, fieldTypeF,
×
UNCOV
224
                        append([]byte{version}, base32Addr...))
×
UNCOV
225
                if err != nil {
×
226
                        return err
×
227
                }
×
228
        }
229

230
        for _, routeHint := range invoice.RouteHints {
8✔
231
                // Each hop hint is encoded using 51 bytes, so we'll make to
4✔
232
                // sure to allocate enough space for the whole route hint.
4✔
233
                routeHintBase256 := make([]byte, 0, hopHintLen*len(routeHint))
4✔
234

4✔
235
                for _, hopHint := range routeHint {
8✔
236
                        hopHintBase256 := make([]byte, hopHintLen)
4✔
237
                        copy(hopHintBase256[:33], hopHint.NodeID.SerializeCompressed())
4✔
238
                        binary.BigEndian.PutUint64(
4✔
239
                                hopHintBase256[33:41], hopHint.ChannelID,
4✔
240
                        )
4✔
241
                        binary.BigEndian.PutUint32(
4✔
242
                                hopHintBase256[41:45], hopHint.FeeBaseMSat,
4✔
243
                        )
4✔
244
                        binary.BigEndian.PutUint32(
4✔
245
                                hopHintBase256[45:49], hopHint.FeeProportionalMillionths,
4✔
246
                        )
4✔
247
                        binary.BigEndian.PutUint16(
4✔
248
                                hopHintBase256[49:51], hopHint.CLTVExpiryDelta,
4✔
249
                        )
4✔
250
                        routeHintBase256 = append(routeHintBase256, hopHintBase256...)
4✔
251
                }
4✔
252

253
                routeHintBase32, err := bech32.ConvertBits(
4✔
254
                        routeHintBase256, 8, 5, true,
4✔
255
                )
4✔
256
                if err != nil {
4✔
257
                        return err
×
258
                }
×
259

260
                err = writeTaggedField(bufferBase32, fieldTypeR, routeHintBase32)
4✔
261
                if err != nil {
4✔
262
                        return err
×
263
                }
×
264
        }
265

266
        for _, path := range invoice.BlindedPaymentPaths {
8✔
267
                var buf bytes.Buffer
4✔
268

4✔
269
                err := path.Encode(&buf)
4✔
270
                if err != nil {
4✔
271
                        return err
×
272
                }
×
273

274
                blindedPathBase32, err := bech32.ConvertBits(
4✔
275
                        buf.Bytes(), 8, 5, true,
4✔
276
                )
4✔
277
                if err != nil {
4✔
278
                        return err
×
279
                }
×
280

281
                err = writeTaggedField(
4✔
282
                        bufferBase32, fieldTypeB, blindedPathBase32,
4✔
283
                )
4✔
284
                if err != nil {
4✔
285
                        return err
×
286
                }
×
287
        }
288

289
        if invoice.Destination != nil {
4✔
UNCOV
290
                // Convert 33 byte pubkey to 53 5-bit groups.
×
UNCOV
291
                pubKeyBase32, err := bech32.ConvertBits(
×
UNCOV
292
                        invoice.Destination.SerializeCompressed(), 8, 5, true)
×
UNCOV
293
                if err != nil {
×
294
                        return err
×
295
                }
×
296

UNCOV
297
                if len(pubKeyBase32) != pubKeyBase32Len {
×
298
                        return fmt.Errorf("invalid pubkey length: %d",
×
299
                                len(invoice.Destination.SerializeCompressed()))
×
300
                }
×
301

UNCOV
302
                err = writeTaggedField(bufferBase32, fieldTypeN, pubKeyBase32)
×
UNCOV
303
                if err != nil {
×
304
                        return err
×
305
                }
×
306
        }
307

308
        err := fn.MapOptionZ(invoice.PaymentAddr, func(addr [32]byte) error {
8✔
309
                return writeBytes32(bufferBase32, fieldTypeS, addr)
4✔
310
        })
4✔
311
        if err != nil {
4✔
312
                return err
×
313
        }
×
314

315
        if invoice.Features.SerializeSize32() > 0 {
8✔
316
                var b bytes.Buffer
4✔
317
                err := invoice.Features.RawFeatureVector.EncodeBase32(&b)
4✔
318
                if err != nil {
4✔
319
                        return err
×
320
                }
×
321

322
                err = writeTaggedField(bufferBase32, fieldType9, b.Bytes())
4✔
323
                if err != nil {
4✔
324
                        return err
×
325
                }
×
326
        }
327

328
        return nil
4✔
329
}
330

331
// writeBytes32 encodes a 32-byte array as base32 and writes it to bufferBase32
332
// under the passed fieldType.
333
func writeBytes32(bufferBase32 *bytes.Buffer, fieldType byte, b [32]byte) error {
4✔
334
        // Convert 32 byte hash to 52 5-bit groups.
4✔
335
        base32, err := bech32.ConvertBits(b[:], 8, 5, true)
4✔
336
        if err != nil {
4✔
337
                return err
×
338
        }
×
339

340
        return writeTaggedField(bufferBase32, fieldType, base32)
4✔
341
}
342

343
// writeTaggedField takes the type of a tagged data field, and the data of
344
// the tagged field (encoded in base32), and writes the type, length and data
345
// to the buffer.
346
func writeTaggedField(bufferBase32 *bytes.Buffer, dataType byte, data []byte) error {
4✔
347
        // Length must be exactly 10 bits, so add leading zero groups if
4✔
348
        // needed.
4✔
349
        lenBase32 := uint64ToBase32(uint64(len(data)))
4✔
350
        for len(lenBase32) < 2 {
8✔
351
                lenBase32 = append([]byte{0}, lenBase32...)
4✔
352
        }
4✔
353

354
        if len(lenBase32) != 2 {
4✔
355
                return fmt.Errorf("data length too big to fit within 10 bits: %d",
×
356
                        len(data))
×
357
        }
×
358

359
        err := bufferBase32.WriteByte(dataType)
4✔
360
        if err != nil {
4✔
361
                return fmt.Errorf("unable to write to buffer: %w", err)
×
362
        }
×
363
        _, err = bufferBase32.Write(lenBase32)
4✔
364
        if err != nil {
4✔
365
                return fmt.Errorf("unable to write to buffer: %w", err)
×
366
        }
×
367
        _, err = bufferBase32.Write(data)
4✔
368
        if err != nil {
4✔
369
                return fmt.Errorf("unable to write to buffer: %w", err)
×
370
        }
×
371

372
        return nil
4✔
373
}
374

375
// uint64ToBase32 converts a uint64 to a base32 encoded integer encoded using
376
// as few 5-bit groups as possible.
377
func uint64ToBase32(num uint64) []byte {
4✔
378
        // Return at least one group.
4✔
379
        if num == 0 {
8✔
380
                return []byte{0}
4✔
381
        }
4✔
382

383
        // To fit an uint64, we need at most is ceil(64 / 5) = 13 groups.
384
        arr := make([]byte, 13)
4✔
385
        i := 13
4✔
386
        for num > 0 {
8✔
387
                i--
4✔
388
                arr[i] = byte(num & uint64(31)) // 0b11111 in binary
4✔
389
                num >>= 5
4✔
390
        }
4✔
391

392
        // We only return non-zero leading groups.
393
        return arr[i:]
4✔
394
}
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc