2017-11-28 03:12:09 +03:00
|
|
|
// Copyright (c) 2013-2017 The btcsuite developers
|
|
|
|
// Copyright (c) 2015-2016 The Decred developers
|
|
|
|
// Copyright (C) 2015-2017 The Lightning Network Developers
|
|
|
|
|
2019-01-24 16:28:25 +03:00
|
|
|
package lnd
|
2015-12-17 03:42:52 +03:00
|
|
|
|
2015-12-30 03:23:27 +03:00
|
|
|
import (
|
2017-08-14 23:54:06 +03:00
|
|
|
"bytes"
|
2019-09-29 02:07:37 +03:00
|
|
|
"context"
|
2018-02-24 05:24:23 +03:00
|
|
|
"crypto/ecdsa"
|
|
|
|
"crypto/elliptic"
|
2017-06-06 01:18:06 +03:00
|
|
|
"crypto/rand"
|
2017-08-14 23:54:06 +03:00
|
|
|
"crypto/tls"
|
|
|
|
"crypto/x509"
|
|
|
|
"crypto/x509/pkix"
|
|
|
|
"encoding/pem"
|
2015-12-30 03:23:27 +03:00
|
|
|
"fmt"
|
2017-07-26 02:22:06 +03:00
|
|
|
"io/ioutil"
|
2017-08-14 23:54:06 +03:00
|
|
|
"math/big"
|
2015-12-30 03:23:27 +03:00
|
|
|
"net"
|
2016-01-17 06:09:41 +03:00
|
|
|
"net/http"
|
2015-12-30 05:59:16 +03:00
|
|
|
"os"
|
2018-01-06 00:43:47 +03:00
|
|
|
"path/filepath"
|
2017-10-15 03:08:27 +03:00
|
|
|
"runtime/pprof"
|
2018-03-15 12:04:17 +03:00
|
|
|
"strings"
|
2017-12-17 20:28:38 +03:00
|
|
|
"sync"
|
2017-06-06 01:18:06 +03:00
|
|
|
"time"
|
2015-12-30 03:23:27 +03:00
|
|
|
|
2019-01-24 16:28:25 +03:00
|
|
|
// Blank import to set up profiling HTTP handlers.
|
|
|
|
_ "net/http/pprof"
|
|
|
|
|
2018-01-16 19:18:41 +03:00
|
|
|
"gopkg.in/macaroon-bakery.v2/bakery"
|
2017-08-18 04:50:57 +03:00
|
|
|
|
2016-03-23 04:50:11 +03:00
|
|
|
"google.golang.org/grpc"
|
2017-07-26 02:22:06 +03:00
|
|
|
"google.golang.org/grpc/credentials"
|
2016-03-23 04:50:11 +03:00
|
|
|
|
2018-08-02 02:02:47 +03:00
|
|
|
"github.com/btcsuite/btcd/btcec"
|
2019-06-14 03:31:55 +03:00
|
|
|
"github.com/btcsuite/btcutil"
|
2018-08-02 02:02:47 +03:00
|
|
|
"github.com/btcsuite/btcwallet/wallet"
|
2016-10-16 00:38:47 +03:00
|
|
|
proxy "github.com/grpc-ecosystem/grpc-gateway/runtime"
|
2019-02-12 05:35:45 +03:00
|
|
|
"github.com/lightninglabs/neutrino"
|
2018-09-20 13:26:58 +03:00
|
|
|
|
2018-12-13 14:26:29 +03:00
|
|
|
"github.com/lightningnetwork/lnd/autopilot"
|
2018-09-20 13:26:58 +03:00
|
|
|
"github.com/lightningnetwork/lnd/build"
|
2019-08-08 05:17:50 +03:00
|
|
|
"github.com/lightningnetwork/lnd/chanacceptor"
|
2016-03-23 04:50:11 +03:00
|
|
|
"github.com/lightningnetwork/lnd/channeldb"
|
2018-02-18 02:40:10 +03:00
|
|
|
"github.com/lightningnetwork/lnd/keychain"
|
2018-05-23 16:41:16 +03:00
|
|
|
"github.com/lightningnetwork/lnd/lncfg"
|
2016-01-16 21:38:48 +03:00
|
|
|
"github.com/lightningnetwork/lnd/lnrpc"
|
2017-06-06 01:18:06 +03:00
|
|
|
"github.com/lightningnetwork/lnd/lnwallet"
|
2018-02-02 07:49:34 +03:00
|
|
|
"github.com/lightningnetwork/lnd/lnwallet/btcwallet"
|
2017-08-18 04:50:57 +03:00
|
|
|
"github.com/lightningnetwork/lnd/macaroons"
|
2018-06-15 06:16:20 +03:00
|
|
|
"github.com/lightningnetwork/lnd/signal"
|
2017-10-12 12:37:37 +03:00
|
|
|
"github.com/lightningnetwork/lnd/walletunlocker"
|
2019-06-14 03:31:55 +03:00
|
|
|
"github.com/lightningnetwork/lnd/watchtower"
|
2019-06-14 03:29:47 +03:00
|
|
|
"github.com/lightningnetwork/lnd/watchtower/wtdb"
|
2015-12-30 03:23:27 +03:00
|
|
|
)
|
|
|
|
|
2017-07-26 02:22:06 +03:00
|
|
|
const (
|
2017-08-14 23:54:06 +03:00
|
|
|
// Make certificate valid for 14 months.
|
|
|
|
autogenCertValidity = 14 /*months*/ * 30 /*days*/ * 24 * time.Hour
|
2017-07-26 02:22:06 +03:00
|
|
|
)
|
|
|
|
|
2016-03-23 04:50:11 +03:00
|
|
|
var (
|
2017-05-03 05:49:14 +03:00
|
|
|
cfg *config
|
|
|
|
registeredChains = newChainRegistry()
|
2017-08-14 23:54:06 +03:00
|
|
|
|
2018-08-22 22:27:16 +03:00
|
|
|
// networkDir is the path to the directory of the currently active
|
|
|
|
// network. This path will hold the files related to each different
|
|
|
|
// network.
|
|
|
|
networkDir string
|
2017-08-22 10:03:03 +03:00
|
|
|
|
2017-08-14 23:54:06 +03:00
|
|
|
// End of ASN.1 time.
|
|
|
|
endOfTime = time.Date(2049, 12, 31, 23, 59, 59, 0, time.UTC)
|
|
|
|
|
|
|
|
// Max serial number.
|
|
|
|
serialNumberLimit = new(big.Int).Lsh(big.NewInt(1), 128)
|
2017-10-12 12:37:37 +03:00
|
|
|
|
|
|
|
/*
|
|
|
|
* These cipher suites fit the following criteria:
|
|
|
|
* - Don't use outdated algorithms like SHA-1 and 3DES
|
|
|
|
* - Don't use ECB mode or other insecure symmetric methods
|
|
|
|
* - Included in the TLS v1.2 suite
|
|
|
|
* - Are available in the Go 1.7.6 standard library (more are
|
|
|
|
* available in 1.8.3 and will be added after lnd no longer
|
|
|
|
* supports 1.7, including suites that support CBC mode)
|
|
|
|
**/
|
|
|
|
tlsCipherSuites = []uint16{
|
|
|
|
tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,
|
|
|
|
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
|
2018-02-24 05:24:23 +03:00
|
|
|
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
|
2017-10-12 12:37:37 +03:00
|
|
|
tls.TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,
|
|
|
|
}
|
2016-03-23 04:50:11 +03:00
|
|
|
)
|
|
|
|
|
2019-07-09 15:04:51 +03:00
|
|
|
// ListenerCfg is a wrapper around custom listeners that can be passed to lnd
|
|
|
|
// when calling its main method.
|
|
|
|
type ListenerCfg struct {
|
|
|
|
// WalletUnlocker can be set to the listener to use for the wallet
|
|
|
|
// unlocker. If nil a regular network listener will be created.
|
|
|
|
WalletUnlocker net.Listener
|
|
|
|
|
|
|
|
// RPCListener can be set to the listener to use for the RPC server. If
|
|
|
|
// nil a regular network listener will be created.
|
|
|
|
RPCListener net.Listener
|
|
|
|
}
|
|
|
|
|
2019-07-09 12:09:19 +03:00
|
|
|
// rpcListeners is a function type used for closures that fetches a set of RPC
|
|
|
|
// listeners for the current configuration, and the GRPC server options to use
|
|
|
|
// with these listeners. If no custom listeners are present, this should return
|
|
|
|
// normal listeners from the RPC endpoints defined in the config, and server
|
|
|
|
// options specifying TLS.
|
|
|
|
type rpcListeners func() ([]net.Listener, func(), []grpc.ServerOption, error)
|
|
|
|
|
2019-01-24 16:28:25 +03:00
|
|
|
// Main is the true entry point for lnd. This function is required since defers
|
|
|
|
// created in the top-level scope of a main method aren't executed if os.Exit()
|
|
|
|
// is called.
|
2019-07-09 15:04:51 +03:00
|
|
|
func Main(lisCfg ListenerCfg) error {
|
2016-03-23 04:50:11 +03:00
|
|
|
// Load the configuration, and parse any command line options. This
|
|
|
|
// function will also set up logging properly.
|
2016-02-23 05:24:56 +03:00
|
|
|
loadedConfig, err := loadConfig()
|
|
|
|
if err != nil {
|
2016-07-13 03:03:29 +03:00
|
|
|
return err
|
2016-02-23 05:24:56 +03:00
|
|
|
}
|
2016-03-23 04:50:11 +03:00
|
|
|
cfg = loadedConfig
|
2017-06-21 18:07:44 +03:00
|
|
|
defer func() {
|
|
|
|
if logRotator != nil {
|
2018-09-20 13:24:53 +03:00
|
|
|
ltndLog.Info("Shutdown complete")
|
2017-06-21 18:07:44 +03:00
|
|
|
logRotator.Close()
|
|
|
|
}
|
|
|
|
}()
|
2016-03-23 04:50:11 +03:00
|
|
|
|
|
|
|
// Show version at startup.
|
2018-09-20 13:26:58 +03:00
|
|
|
ltndLog.Infof("Version: %s, build=%s, logging=%s",
|
|
|
|
build.Version(), build.Deployment, build.LoggingType)
|
2016-02-23 05:24:56 +03:00
|
|
|
|
2018-03-15 12:04:17 +03:00
|
|
|
var network string
|
|
|
|
switch {
|
|
|
|
case cfg.Bitcoin.TestNet3 || cfg.Litecoin.TestNet3:
|
|
|
|
network = "testnet"
|
|
|
|
|
|
|
|
case cfg.Bitcoin.MainNet || cfg.Litecoin.MainNet:
|
|
|
|
network = "mainnet"
|
|
|
|
|
2018-09-14 09:03:09 +03:00
|
|
|
case cfg.Bitcoin.SimNet || cfg.Litecoin.SimNet:
|
2018-05-24 04:24:01 +03:00
|
|
|
network = "simnet"
|
2018-03-15 12:04:17 +03:00
|
|
|
|
2018-11-30 00:53:01 +03:00
|
|
|
case cfg.Bitcoin.RegTest || cfg.Litecoin.RegTest:
|
2018-03-15 12:04:17 +03:00
|
|
|
network = "regtest"
|
|
|
|
}
|
|
|
|
|
|
|
|
ltndLog.Infof("Active chain: %v (network=%v)",
|
|
|
|
strings.Title(registeredChains.PrimaryChain().String()),
|
|
|
|
network,
|
|
|
|
)
|
|
|
|
|
2016-06-21 07:42:07 +03:00
|
|
|
// Enable http profiling server if requested.
|
|
|
|
if cfg.Profile != "" {
|
|
|
|
go func() {
|
|
|
|
listenAddr := net.JoinHostPort("", cfg.Profile)
|
|
|
|
profileRedirect := http.RedirectHandler("/debug/pprof",
|
|
|
|
http.StatusSeeOther)
|
|
|
|
http.Handle("/", profileRedirect)
|
|
|
|
fmt.Println(http.ListenAndServe(listenAddr, nil))
|
|
|
|
}()
|
|
|
|
}
|
2016-01-17 06:01:06 +03:00
|
|
|
|
2017-10-15 03:08:27 +03:00
|
|
|
// Write cpu profile if requested.
|
|
|
|
if cfg.CPUProfile != "" {
|
|
|
|
f, err := os.Create(cfg.CPUProfile)
|
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to create CPU profile: %v",
|
|
|
|
err)
|
|
|
|
ltndLog.Error(err)
|
2017-10-15 03:08:27 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
pprof.StartCPUProfile(f)
|
|
|
|
defer f.Close()
|
|
|
|
defer pprof.StopCPUProfile()
|
|
|
|
}
|
|
|
|
|
2018-01-06 00:43:47 +03:00
|
|
|
// Create the network-segmented directory for the channel database.
|
|
|
|
graphDir := filepath.Join(cfg.DataDir,
|
|
|
|
defaultGraphSubDirname,
|
|
|
|
normalizeNetwork(activeNetParams.Name))
|
|
|
|
|
2016-03-23 04:50:11 +03:00
|
|
|
// Open the channeldb, which is dedicated to storing channel, and
|
2017-01-13 08:01:50 +03:00
|
|
|
// network related metadata.
|
2019-04-02 02:34:30 +03:00
|
|
|
chanDB, err := channeldb.Open(
|
|
|
|
graphDir,
|
|
|
|
channeldb.OptionSetRejectCacheSize(cfg.Caches.RejectCacheSize),
|
|
|
|
channeldb.OptionSetChannelCacheSize(cfg.Caches.ChannelCacheSize),
|
|
|
|
)
|
2016-03-23 04:50:11 +03:00
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to open channeldb: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2016-07-13 03:03:29 +03:00
|
|
|
return err
|
2016-03-23 04:50:11 +03:00
|
|
|
}
|
|
|
|
defer chanDB.Close()
|
|
|
|
|
2017-08-18 04:50:57 +03:00
|
|
|
// Only process macaroons if --no-macaroons isn't set.
|
2018-01-16 19:18:41 +03:00
|
|
|
ctx := context.Background()
|
|
|
|
ctx, cancel := context.WithCancel(ctx)
|
|
|
|
defer cancel()
|
|
|
|
|
2019-06-23 07:07:10 +03:00
|
|
|
tlsCfg, restCreds, restProxyDest, err := getTLSConfig(
|
2019-07-22 10:26:25 +03:00
|
|
|
cfg.TLSCertPath, cfg.TLSKeyPath, cfg.TLSExtraIPs,
|
|
|
|
cfg.TLSExtraDomains, cfg.RPCListeners,
|
2019-06-23 07:07:10 +03:00
|
|
|
)
|
2017-10-12 12:37:37 +03:00
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to load TLS credentials: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2017-10-12 12:37:37 +03:00
|
|
|
return err
|
|
|
|
}
|
2019-01-30 11:09:57 +03:00
|
|
|
|
|
|
|
serverCreds := credentials.NewTLS(tlsCfg)
|
|
|
|
serverOpts := []grpc.ServerOption{grpc.Creds(serverCreds)}
|
|
|
|
|
2019-08-07 03:20:37 +03:00
|
|
|
// For our REST dial options, we'll still use TLS, but also increase
|
|
|
|
// the max message size that we'll decode to allow clients to hit
|
|
|
|
// endpoints which return more data such as the DescribeGraph call.
|
|
|
|
restDialOpts := []grpc.DialOption{
|
|
|
|
grpc.WithTransportCredentials(*restCreds),
|
|
|
|
grpc.WithDefaultCallOptions(
|
|
|
|
grpc.MaxCallRecvMsgSize(1 * 1024 * 1024 * 50),
|
|
|
|
),
|
|
|
|
}
|
2017-10-12 12:37:37 +03:00
|
|
|
|
2019-03-14 03:20:29 +03:00
|
|
|
// Before starting the wallet, we'll create and start our Neutrino
|
|
|
|
// light client instance, if enabled, in order to allow it to sync
|
|
|
|
// while the rest of the daemon continues startup.
|
2019-02-12 05:35:45 +03:00
|
|
|
mainChain := cfg.Bitcoin
|
|
|
|
if registeredChains.PrimaryChain() == litecoinChain {
|
|
|
|
mainChain = cfg.Litecoin
|
|
|
|
}
|
|
|
|
var neutrinoCS *neutrino.ChainService
|
|
|
|
if mainChain.Node == "neutrino" {
|
2019-03-14 03:20:29 +03:00
|
|
|
neutrinoBackend, neutrinoCleanUp, err := initNeutrinoBackend(
|
2019-02-12 05:35:45 +03:00
|
|
|
mainChain.ChainDir,
|
|
|
|
)
|
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to initialize neutrino "+
|
|
|
|
"backend: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2019-03-14 03:20:29 +03:00
|
|
|
return err
|
2019-02-12 05:35:45 +03:00
|
|
|
}
|
2019-07-15 23:32:37 +03:00
|
|
|
defer neutrinoCleanUp()
|
2019-03-14 03:20:29 +03:00
|
|
|
neutrinoCS = neutrinoBackend
|
2019-02-12 05:35:45 +03:00
|
|
|
}
|
|
|
|
|
2018-03-27 00:12:17 +03:00
|
|
|
var (
|
2018-12-10 07:08:32 +03:00
|
|
|
walletInitParams WalletUnlockParams
|
|
|
|
privateWalletPw = lnwallet.DefaultPrivatePassphrase
|
|
|
|
publicWalletPw = lnwallet.DefaultPublicPassphrase
|
2018-03-27 00:12:17 +03:00
|
|
|
)
|
|
|
|
|
2018-12-10 07:08:32 +03:00
|
|
|
// If the user didn't request a seed, then we'll manually assume a
|
|
|
|
// wallet birthday of now, as otherwise the seed would've specified
|
|
|
|
// this information.
|
|
|
|
walletInitParams.Birthday = time.Now()
|
|
|
|
|
2019-07-09 12:09:19 +03:00
|
|
|
// getListeners is a closure that creates listeners from the
|
|
|
|
// RPCListeners defined in the config. It also returns a cleanup
|
|
|
|
// closure and the server options to use for the GRPC server.
|
|
|
|
getListeners := func() ([]net.Listener, func(), []grpc.ServerOption,
|
|
|
|
error) {
|
|
|
|
|
|
|
|
var grpcListeners []net.Listener
|
|
|
|
for _, grpcEndpoint := range cfg.RPCListeners {
|
|
|
|
// Start a gRPC server listening for HTTP/2
|
|
|
|
// connections.
|
|
|
|
lis, err := lncfg.ListenOnAddress(grpcEndpoint)
|
|
|
|
if err != nil {
|
|
|
|
ltndLog.Errorf("unable to listen on %s",
|
|
|
|
grpcEndpoint)
|
|
|
|
return nil, nil, nil, err
|
|
|
|
}
|
|
|
|
grpcListeners = append(grpcListeners, lis)
|
|
|
|
}
|
|
|
|
|
|
|
|
cleanup := func() {
|
|
|
|
for _, lis := range grpcListeners {
|
|
|
|
lis.Close()
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return grpcListeners, cleanup, serverOpts, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// walletUnlockerListeners is a closure we'll hand to the wallet
|
|
|
|
// unlocker, that will be called when it needs listeners for its GPRC
|
|
|
|
// server.
|
|
|
|
walletUnlockerListeners := func() ([]net.Listener, func(),
|
|
|
|
[]grpc.ServerOption, error) {
|
|
|
|
|
2019-07-09 15:04:51 +03:00
|
|
|
// If we have chosen to start with a dedicated listener for the
|
|
|
|
// wallet unlocker, we return it directly, and empty server
|
|
|
|
// options to deactivate TLS.
|
|
|
|
// TODO(halseth): any point in adding TLS support for custom
|
|
|
|
// listeners?
|
|
|
|
if lisCfg.WalletUnlocker != nil {
|
|
|
|
return []net.Listener{lisCfg.WalletUnlocker}, func() {},
|
|
|
|
[]grpc.ServerOption{}, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// Otherwise we'll return the regular listeners.
|
2019-07-09 12:09:19 +03:00
|
|
|
return getListeners()
|
|
|
|
}
|
|
|
|
|
2017-10-12 12:37:37 +03:00
|
|
|
// We wait until the user provides a password over RPC. In case lnd is
|
2018-09-05 04:53:14 +03:00
|
|
|
// started with the --noseedbackup flag, we use the default password
|
2018-04-20 10:06:06 +03:00
|
|
|
// for wallet encryption.
|
2018-09-05 04:53:14 +03:00
|
|
|
if !cfg.NoSeedBackup {
|
2018-12-10 07:08:32 +03:00
|
|
|
params, err := waitForWalletPassword(
|
2019-07-09 12:09:19 +03:00
|
|
|
cfg.RESTListeners, restDialOpts, restProxyDest, tlsCfg,
|
|
|
|
walletUnlockerListeners,
|
2017-10-20 05:53:19 +03:00
|
|
|
)
|
2017-10-12 12:37:37 +03:00
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to set up wallet password "+
|
|
|
|
"listeners: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2017-10-12 12:37:37 +03:00
|
|
|
return err
|
|
|
|
}
|
2018-03-27 00:12:17 +03:00
|
|
|
|
2018-12-10 07:08:32 +03:00
|
|
|
walletInitParams = *params
|
2018-03-27 00:12:17 +03:00
|
|
|
privateWalletPw = walletInitParams.Password
|
|
|
|
publicWalletPw = walletInitParams.Password
|
|
|
|
|
2018-12-10 07:08:32 +03:00
|
|
|
if walletInitParams.RecoveryWindow > 0 {
|
2018-03-27 00:12:17 +03:00
|
|
|
ltndLog.Infof("Wallet recovery mode enabled with "+
|
|
|
|
"address lookahead of %d addresses",
|
2018-12-10 07:08:32 +03:00
|
|
|
walletInitParams.RecoveryWindow)
|
2018-03-27 00:12:17 +03:00
|
|
|
}
|
2017-10-12 12:37:37 +03:00
|
|
|
}
|
|
|
|
|
2018-04-20 10:06:06 +03:00
|
|
|
var macaroonService *macaroons.Service
|
2018-02-01 03:04:56 +03:00
|
|
|
if !cfg.NoMacaroons {
|
2018-04-20 10:06:06 +03:00
|
|
|
// Create the macaroon authentication/authorization service.
|
2018-08-22 22:27:16 +03:00
|
|
|
macaroonService, err = macaroons.NewService(
|
|
|
|
networkDir, macaroons.IPLockChecker,
|
|
|
|
)
|
2018-04-20 10:06:06 +03:00
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to set up macaroon "+
|
|
|
|
"authentication: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2018-04-20 10:06:06 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
defer macaroonService.Close()
|
|
|
|
|
2018-02-01 03:04:56 +03:00
|
|
|
// Try to unlock the macaroon store with the private password.
|
|
|
|
err = macaroonService.CreateUnlock(&privateWalletPw)
|
2018-04-20 10:06:06 +03:00
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to unlock macaroons: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2018-02-01 03:04:56 +03:00
|
|
|
return err
|
|
|
|
}
|
2018-03-21 02:50:08 +03:00
|
|
|
|
2018-02-01 03:04:56 +03:00
|
|
|
// Create macaroon files for lncli to use if they don't exist.
|
2018-03-21 02:50:08 +03:00
|
|
|
if !fileExists(cfg.AdminMacPath) && !fileExists(cfg.ReadMacPath) &&
|
|
|
|
!fileExists(cfg.InvoiceMacPath) {
|
|
|
|
|
|
|
|
err = genMacaroons(
|
|
|
|
ctx, macaroonService, cfg.AdminMacPath,
|
|
|
|
cfg.ReadMacPath, cfg.InvoiceMacPath,
|
|
|
|
)
|
2018-02-01 03:04:56 +03:00
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to create macaroons "+
|
|
|
|
"%v", err)
|
|
|
|
ltndLog.Error(err)
|
2018-02-01 03:04:56 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2017-05-18 21:49:32 +03:00
|
|
|
// With the information parsed from the configuration, create valid
|
2017-08-22 10:03:03 +03:00
|
|
|
// instances of the pertinent interfaces required to operate the
|
2017-05-18 21:49:32 +03:00
|
|
|
// Lightning Network Daemon.
|
2019-04-11 03:32:41 +03:00
|
|
|
activeChainControl, err := newChainControlFromConfig(
|
2018-12-10 07:08:32 +03:00
|
|
|
cfg, chanDB, privateWalletPw, publicWalletPw,
|
|
|
|
walletInitParams.Birthday, walletInitParams.RecoveryWindow,
|
|
|
|
walletInitParams.Wallet, neutrinoCS,
|
2018-03-27 00:12:17 +03:00
|
|
|
)
|
2015-12-30 03:23:27 +03:00
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to create chain control: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2016-07-13 03:03:29 +03:00
|
|
|
return err
|
2015-12-30 03:23:27 +03:00
|
|
|
}
|
2017-03-27 20:25:44 +03:00
|
|
|
|
2017-05-03 05:49:14 +03:00
|
|
|
// Finally before we start the server, we'll register the "holy
|
|
|
|
// trinity" of interface for our current "home chain" with the active
|
|
|
|
// chainRegistry interface.
|
|
|
|
primaryChain := registeredChains.PrimaryChain()
|
2017-05-18 21:49:32 +03:00
|
|
|
registeredChains.RegisterChain(primaryChain, activeChainControl)
|
2017-05-03 05:49:14 +03:00
|
|
|
|
2018-02-18 02:40:10 +03:00
|
|
|
// TODO(roasbeef): add rotation
|
|
|
|
idPrivKey, err := activeChainControl.wallet.DerivePrivKey(keychain.KeyDescriptor{
|
|
|
|
KeyLocator: keychain.KeyLocator{
|
|
|
|
Family: keychain.KeyFamilyNodeKey,
|
|
|
|
Index: 0,
|
|
|
|
},
|
|
|
|
})
|
2017-06-06 01:18:06 +03:00
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to derive node private key: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2017-06-06 01:18:06 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
idPrivKey.Curve = btcec.S256()
|
|
|
|
|
2018-04-27 23:54:35 +03:00
|
|
|
if cfg.Tor.Active {
|
2018-02-06 05:36:11 +03:00
|
|
|
srvrLog.Infof("Proxying all network traffic via Tor "+
|
2018-04-27 23:54:35 +03:00
|
|
|
"(stream_isolation=%v)! NOTE: Ensure the backend node "+
|
|
|
|
"is proxying over Tor as well", cfg.Tor.StreamIsolation)
|
2018-02-06 05:36:11 +03:00
|
|
|
}
|
|
|
|
|
2019-06-14 03:29:47 +03:00
|
|
|
// If the watchtower client should be active, open the client database.
|
|
|
|
// This is done here so that Close always executes when lndMain returns.
|
|
|
|
var towerClientDB *wtdb.ClientDB
|
2019-07-04 05:54:28 +03:00
|
|
|
if cfg.WtClient.Active {
|
2019-06-14 03:29:47 +03:00
|
|
|
var err error
|
|
|
|
towerClientDB, err = wtdb.OpenClientDB(graphDir)
|
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to open watchtower client "+
|
|
|
|
"database: %v", err)
|
|
|
|
ltndLog.Error(err)
|
|
|
|
return err
|
2019-06-14 03:29:47 +03:00
|
|
|
}
|
|
|
|
defer towerClientDB.Close()
|
|
|
|
}
|
|
|
|
|
2019-06-14 03:31:55 +03:00
|
|
|
var tower *watchtower.Standalone
|
|
|
|
if cfg.Watchtower.Active {
|
|
|
|
// Segment the watchtower directory by chain and network.
|
|
|
|
towerDBDir := filepath.Join(
|
|
|
|
cfg.Watchtower.TowerDir,
|
|
|
|
registeredChains.PrimaryChain().String(),
|
|
|
|
normalizeNetwork(activeNetParams.Name),
|
|
|
|
)
|
|
|
|
|
|
|
|
towerDB, err := wtdb.OpenTowerDB(towerDBDir)
|
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to open watchtower "+
|
|
|
|
"database: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2019-06-14 03:31:55 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
defer towerDB.Close()
|
|
|
|
|
2019-06-21 02:55:52 +03:00
|
|
|
towerPrivKey, err := activeChainControl.wallet.DerivePrivKey(
|
|
|
|
keychain.KeyDescriptor{
|
|
|
|
KeyLocator: keychain.KeyLocator{
|
|
|
|
Family: keychain.KeyFamilyTowerID,
|
|
|
|
Index: 0,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
)
|
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to derive watchtower "+
|
|
|
|
"private key: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2019-06-21 02:55:52 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2019-06-14 03:31:55 +03:00
|
|
|
wtConfig, err := cfg.Watchtower.Apply(&watchtower.Config{
|
|
|
|
BlockFetcher: activeChainControl.chainIO,
|
|
|
|
DB: towerDB,
|
|
|
|
EpochRegistrar: activeChainControl.chainNotifier,
|
|
|
|
Net: cfg.net,
|
|
|
|
NewAddress: func() (btcutil.Address, error) {
|
|
|
|
return activeChainControl.wallet.NewAddress(
|
|
|
|
lnwallet.WitnessPubKey, false,
|
|
|
|
)
|
|
|
|
},
|
2019-06-21 02:55:52 +03:00
|
|
|
NodePrivKey: towerPrivKey,
|
2019-06-14 03:31:55 +03:00
|
|
|
PublishTx: activeChainControl.wallet.PublishTransaction,
|
|
|
|
ChainHash: *activeNetParams.GenesisHash,
|
|
|
|
}, lncfg.NormalizeAddresses)
|
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to configure watchtower: %v",
|
|
|
|
err)
|
|
|
|
ltndLog.Error(err)
|
2019-06-14 03:31:55 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
tower, err = watchtower.New(wtConfig)
|
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to create watchtower: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2019-06-14 03:31:55 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-08-08 05:17:50 +03:00
|
|
|
// Initialize the ChainedAcceptor.
|
|
|
|
chainedAcceptor := chanacceptor.NewChainedAcceptor()
|
|
|
|
|
2017-05-18 21:49:32 +03:00
|
|
|
// Set up the core server which will listen for incoming peer
|
|
|
|
// connections.
|
2018-02-18 02:40:10 +03:00
|
|
|
server, err := newServer(
|
2019-06-14 03:29:47 +03:00
|
|
|
cfg.Listeners, chanDB, towerClientDB, activeChainControl,
|
2019-08-08 05:18:23 +03:00
|
|
|
idPrivKey, walletInitParams.ChansToRestore, chainedAcceptor,
|
2018-02-18 02:40:10 +03:00
|
|
|
)
|
2016-01-17 06:09:41 +03:00
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to create server: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2016-07-13 03:03:29 +03:00
|
|
|
return err
|
2016-01-17 06:09:41 +03:00
|
|
|
}
|
2017-06-06 01:18:06 +03:00
|
|
|
|
2019-01-09 11:14:45 +03:00
|
|
|
// Set up an autopilot manager from the current config. This will be
|
2018-12-13 14:26:29 +03:00
|
|
|
// used to manage the underlying autopilot agent, starting and stopping
|
|
|
|
// it at will.
|
2019-01-09 11:14:45 +03:00
|
|
|
atplCfg, err := initAutoPilot(server, cfg.Autopilot)
|
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to initialize autopilot: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2019-01-09 11:14:45 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2018-12-13 14:26:29 +03:00
|
|
|
atplManager, err := autopilot.NewManager(atplCfg)
|
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to create autopilot manager: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2018-12-13 14:26:29 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
if err := atplManager.Start(); err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to start autopilot manager: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2018-12-13 14:26:29 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
defer atplManager.Stop()
|
|
|
|
|
2019-07-09 12:09:19 +03:00
|
|
|
// rpcListeners is a closure we'll hand to the rpc server, that will be
|
|
|
|
// called when it needs listeners for its GPRC server.
|
|
|
|
rpcListeners := func() ([]net.Listener, func(), []grpc.ServerOption,
|
|
|
|
error) {
|
|
|
|
|
2019-07-09 15:04:51 +03:00
|
|
|
// If we have chosen to start with a dedicated listener for the
|
|
|
|
// rpc server, we return it directly, and empty server options
|
|
|
|
// to deactivate TLS.
|
|
|
|
// TODO(halseth): any point in adding TLS support for custom
|
|
|
|
// listeners?
|
|
|
|
if lisCfg.RPCListener != nil {
|
|
|
|
return []net.Listener{lisCfg.RPCListener}, func() {},
|
|
|
|
[]grpc.ServerOption{}, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// Otherwise we'll return the regular listeners.
|
2019-07-09 12:09:19 +03:00
|
|
|
return getListeners()
|
|
|
|
}
|
|
|
|
|
2017-06-06 01:44:18 +03:00
|
|
|
// Initialize, and register our implementation of the gRPC interface
|
|
|
|
// exported by the rpcServer.
|
lnd+rpc: modify rpcServer to fully manaage listeners and gRPC, handle sub-servers
In this commit, we modify the existing rpcServer to fully manage the
macaroons, gRPC server, and also seek out and create all sub-servers.
With this change, the RPC server gains more responsibility, as it
becomes the "root" server in the hierarchy of gRPC sub-servers.
In addition to creating each sub-server, it will also merge the set of
macaroon permissions for each sub-server, with the permissions of the
rest of the RPC infra. As a result, each sub-server is able to
independently specify what it needs w.r.t macaroon permissions and have
that taken care of by the RPC server. In order to achieve this, we need
to unify the creation of the RPC interceptors, and also fully manage the
gRPC server ourselves.
Some examples with various build configs:
```
⛰i make build
Building debug lnd and lncli.
go build -v -tags="dev" -o lnd-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd
go build -v -tags="dev" -o lncli-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd/cmd/lncli
⛰i ./lnd-debug --debuglevel=debug --signrpc.signermacaroonpath=~/sign.macaroon
unknown flag `signrpc.signermacaroonpath'
unknown flag `signrpc.signermacaroonpath'
⛰i make build tags=signerrpc
Building debug lnd and lncli.
go build -v -tags="dev signerrpc" -o lnd-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd
go build -v -tags="dev signerrpc" -o lncli-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd/cmd/lncli
⛰i ./lnd-debug --debuglevel=debug --signrpc.signermacaroonpath=~/sign.macaroon
2018-10-22 17:31:01.132 [INF] LTND: Version: 0.5.0-beta commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty, build=development, logging=default
2018-10-22 17:31:01.133 [INF] LTND: Active chain: Bitcoin (network=simnet)
2018-10-22 17:31:01.140 [INF] CHDB: Checking for schema update: latest_version=6, db_version=6
2018-10-22 17:31:01.236 [INF] LTND: Primary chain is set to: bitcoin
2018-10-22 17:31:02.391 [INF] LNWL: Opened wallet
2018-10-22 17:31:03.315 [INF] LNWL: The wallet has been unlocked without a time limit
2018-10-22 17:31:03.315 [INF] LTND: LightningWallet opened
2018-10-22 17:31:03.319 [INF] LNWL: Catching up block hashes to height 3060, this will take a while...
2018-10-22 17:31:03.320 [INF] HSWC: Restoring in-memory circuit state from disk
2018-10-22 17:31:03.320 [INF] LNWL: Done catching up block hashes
2018-10-22 17:31:03.320 [INF] HSWC: Payment circuits loaded: num_pending=0, num_open=0
2018-10-22 17:31:03.322 [DBG] LTND: Populating dependencies for sub RPC server: Signrpc
```
As for the config, an example is:
```
[signrpc]
signrpc.signermacaroonpath=~/signer.macaroon
```
2018-10-23 04:03:07 +03:00
|
|
|
rpcServer, err := newRPCServer(
|
2019-07-09 12:09:19 +03:00
|
|
|
server, macaroonService, cfg.SubRPCServers, restDialOpts,
|
|
|
|
restProxyDest, atplManager, server.invoices, tower, tlsCfg,
|
2019-08-08 05:17:50 +03:00
|
|
|
rpcListeners, chainedAcceptor,
|
2018-05-23 16:38:19 +03:00
|
|
|
)
|
2016-10-16 00:38:47 +03:00
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to create RPC server: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2016-10-16 00:38:47 +03:00
|
|
|
return err
|
|
|
|
}
|
lnd+rpc: modify rpcServer to fully manaage listeners and gRPC, handle sub-servers
In this commit, we modify the existing rpcServer to fully manage the
macaroons, gRPC server, and also seek out and create all sub-servers.
With this change, the RPC server gains more responsibility, as it
becomes the "root" server in the hierarchy of gRPC sub-servers.
In addition to creating each sub-server, it will also merge the set of
macaroon permissions for each sub-server, with the permissions of the
rest of the RPC infra. As a result, each sub-server is able to
independently specify what it needs w.r.t macaroon permissions and have
that taken care of by the RPC server. In order to achieve this, we need
to unify the creation of the RPC interceptors, and also fully manage the
gRPC server ourselves.
Some examples with various build configs:
```
⛰i make build
Building debug lnd and lncli.
go build -v -tags="dev" -o lnd-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd
go build -v -tags="dev" -o lncli-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd/cmd/lncli
⛰i ./lnd-debug --debuglevel=debug --signrpc.signermacaroonpath=~/sign.macaroon
unknown flag `signrpc.signermacaroonpath'
unknown flag `signrpc.signermacaroonpath'
⛰i make build tags=signerrpc
Building debug lnd and lncli.
go build -v -tags="dev signerrpc" -o lnd-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd
go build -v -tags="dev signerrpc" -o lncli-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd/cmd/lncli
⛰i ./lnd-debug --debuglevel=debug --signrpc.signermacaroonpath=~/sign.macaroon
2018-10-22 17:31:01.132 [INF] LTND: Version: 0.5.0-beta commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty, build=development, logging=default
2018-10-22 17:31:01.133 [INF] LTND: Active chain: Bitcoin (network=simnet)
2018-10-22 17:31:01.140 [INF] CHDB: Checking for schema update: latest_version=6, db_version=6
2018-10-22 17:31:01.236 [INF] LTND: Primary chain is set to: bitcoin
2018-10-22 17:31:02.391 [INF] LNWL: Opened wallet
2018-10-22 17:31:03.315 [INF] LNWL: The wallet has been unlocked without a time limit
2018-10-22 17:31:03.315 [INF] LTND: LightningWallet opened
2018-10-22 17:31:03.319 [INF] LNWL: Catching up block hashes to height 3060, this will take a while...
2018-10-22 17:31:03.320 [INF] HSWC: Restoring in-memory circuit state from disk
2018-10-22 17:31:03.320 [INF] LNWL: Done catching up block hashes
2018-10-22 17:31:03.320 [INF] HSWC: Payment circuits loaded: num_pending=0, num_open=0
2018-10-22 17:31:03.322 [DBG] LTND: Populating dependencies for sub RPC server: Signrpc
```
As for the config, an example is:
```
[signrpc]
signrpc.signermacaroonpath=~/signer.macaroon
```
2018-10-23 04:03:07 +03:00
|
|
|
if err := rpcServer.Start(); err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to start RPC server: %v", err)
|
|
|
|
ltndLog.Error(err)
|
lnd+rpc: modify rpcServer to fully manaage listeners and gRPC, handle sub-servers
In this commit, we modify the existing rpcServer to fully manage the
macaroons, gRPC server, and also seek out and create all sub-servers.
With this change, the RPC server gains more responsibility, as it
becomes the "root" server in the hierarchy of gRPC sub-servers.
In addition to creating each sub-server, it will also merge the set of
macaroon permissions for each sub-server, with the permissions of the
rest of the RPC infra. As a result, each sub-server is able to
independently specify what it needs w.r.t macaroon permissions and have
that taken care of by the RPC server. In order to achieve this, we need
to unify the creation of the RPC interceptors, and also fully manage the
gRPC server ourselves.
Some examples with various build configs:
```
⛰i make build
Building debug lnd and lncli.
go build -v -tags="dev" -o lnd-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd
go build -v -tags="dev" -o lncli-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd/cmd/lncli
⛰i ./lnd-debug --debuglevel=debug --signrpc.signermacaroonpath=~/sign.macaroon
unknown flag `signrpc.signermacaroonpath'
unknown flag `signrpc.signermacaroonpath'
⛰i make build tags=signerrpc
Building debug lnd and lncli.
go build -v -tags="dev signerrpc" -o lnd-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd
go build -v -tags="dev signerrpc" -o lncli-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd/cmd/lncli
⛰i ./lnd-debug --debuglevel=debug --signrpc.signermacaroonpath=~/sign.macaroon
2018-10-22 17:31:01.132 [INF] LTND: Version: 0.5.0-beta commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty, build=development, logging=default
2018-10-22 17:31:01.133 [INF] LTND: Active chain: Bitcoin (network=simnet)
2018-10-22 17:31:01.140 [INF] CHDB: Checking for schema update: latest_version=6, db_version=6
2018-10-22 17:31:01.236 [INF] LTND: Primary chain is set to: bitcoin
2018-10-22 17:31:02.391 [INF] LNWL: Opened wallet
2018-10-22 17:31:03.315 [INF] LNWL: The wallet has been unlocked without a time limit
2018-10-22 17:31:03.315 [INF] LTND: LightningWallet opened
2018-10-22 17:31:03.319 [INF] LNWL: Catching up block hashes to height 3060, this will take a while...
2018-10-22 17:31:03.320 [INF] HSWC: Restoring in-memory circuit state from disk
2018-10-22 17:31:03.320 [INF] LNWL: Done catching up block hashes
2018-10-22 17:31:03.320 [INF] HSWC: Payment circuits loaded: num_pending=0, num_open=0
2018-10-22 17:31:03.322 [DBG] LTND: Populating dependencies for sub RPC server: Signrpc
```
As for the config, an example is:
```
[signrpc]
signrpc.signermacaroonpath=~/signer.macaroon
```
2018-10-23 04:03:07 +03:00
|
|
|
return err
|
2017-12-17 20:28:38 +03:00
|
|
|
}
|
lnd+rpc: modify rpcServer to fully manaage listeners and gRPC, handle sub-servers
In this commit, we modify the existing rpcServer to fully manage the
macaroons, gRPC server, and also seek out and create all sub-servers.
With this change, the RPC server gains more responsibility, as it
becomes the "root" server in the hierarchy of gRPC sub-servers.
In addition to creating each sub-server, it will also merge the set of
macaroon permissions for each sub-server, with the permissions of the
rest of the RPC infra. As a result, each sub-server is able to
independently specify what it needs w.r.t macaroon permissions and have
that taken care of by the RPC server. In order to achieve this, we need
to unify the creation of the RPC interceptors, and also fully manage the
gRPC server ourselves.
Some examples with various build configs:
```
⛰i make build
Building debug lnd and lncli.
go build -v -tags="dev" -o lnd-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd
go build -v -tags="dev" -o lncli-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd/cmd/lncli
⛰i ./lnd-debug --debuglevel=debug --signrpc.signermacaroonpath=~/sign.macaroon
unknown flag `signrpc.signermacaroonpath'
unknown flag `signrpc.signermacaroonpath'
⛰i make build tags=signerrpc
Building debug lnd and lncli.
go build -v -tags="dev signerrpc" -o lnd-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd
go build -v -tags="dev signerrpc" -o lncli-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd/cmd/lncli
⛰i ./lnd-debug --debuglevel=debug --signrpc.signermacaroonpath=~/sign.macaroon
2018-10-22 17:31:01.132 [INF] LTND: Version: 0.5.0-beta commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty, build=development, logging=default
2018-10-22 17:31:01.133 [INF] LTND: Active chain: Bitcoin (network=simnet)
2018-10-22 17:31:01.140 [INF] CHDB: Checking for schema update: latest_version=6, db_version=6
2018-10-22 17:31:01.236 [INF] LTND: Primary chain is set to: bitcoin
2018-10-22 17:31:02.391 [INF] LNWL: Opened wallet
2018-10-22 17:31:03.315 [INF] LNWL: The wallet has been unlocked without a time limit
2018-10-22 17:31:03.315 [INF] LTND: LightningWallet opened
2018-10-22 17:31:03.319 [INF] LNWL: Catching up block hashes to height 3060, this will take a while...
2018-10-22 17:31:03.320 [INF] HSWC: Restoring in-memory circuit state from disk
2018-10-22 17:31:03.320 [INF] LNWL: Done catching up block hashes
2018-10-22 17:31:03.320 [INF] HSWC: Payment circuits loaded: num_pending=0, num_open=0
2018-10-22 17:31:03.322 [DBG] LTND: Populating dependencies for sub RPC server: Signrpc
```
As for the config, an example is:
```
[signrpc]
signrpc.signermacaroonpath=~/signer.macaroon
```
2018-10-23 04:03:07 +03:00
|
|
|
defer rpcServer.Stop()
|
2016-10-16 00:38:47 +03:00
|
|
|
|
2019-07-23 01:13:42 +03:00
|
|
|
// If we're not in regtest or simnet mode, We'll wait until we're fully
|
|
|
|
// synced to continue the start up of the remainder of the daemon. This
|
|
|
|
// ensures that we don't accept any possibly invalid state transitions, or
|
2017-06-06 01:18:06 +03:00
|
|
|
// accept channels with spent funds.
|
2019-07-23 01:13:42 +03:00
|
|
|
if !(cfg.Bitcoin.RegTest || cfg.Bitcoin.SimNet ||
|
|
|
|
cfg.Litecoin.RegTest || cfg.Litecoin.SimNet) {
|
|
|
|
|
2017-06-06 01:18:06 +03:00
|
|
|
_, bestHeight, err := activeChainControl.chainIO.GetBestBlock()
|
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to determine chain tip: %v",
|
|
|
|
err)
|
|
|
|
ltndLog.Error(err)
|
2017-06-06 01:18:06 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
ltndLog.Infof("Waiting for chain backend to finish sync, "+
|
|
|
|
"start_height=%v", bestHeight)
|
|
|
|
|
|
|
|
for {
|
2018-06-15 06:16:20 +03:00
|
|
|
if !signal.Alive() {
|
2018-05-23 09:55:30 +03:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2017-12-10 10:42:46 +03:00
|
|
|
synced, _, err := activeChainControl.wallet.IsSynced()
|
2017-06-06 01:18:06 +03:00
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to determine if "+
|
|
|
|
"wallet is synced: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2017-06-06 01:18:06 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
if synced {
|
|
|
|
break
|
|
|
|
}
|
|
|
|
|
|
|
|
time.Sleep(time.Second * 1)
|
|
|
|
}
|
|
|
|
|
|
|
|
_, bestHeight, err = activeChainControl.chainIO.GetBestBlock()
|
|
|
|
if err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to determine chain tip: %v",
|
|
|
|
err)
|
|
|
|
ltndLog.Error(err)
|
2017-06-06 01:18:06 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
ltndLog.Infof("Chain backend is fully synced (end_height=%v)!",
|
|
|
|
bestHeight)
|
|
|
|
}
|
|
|
|
|
|
|
|
// With all the relevant chains initialized, we can finally start the
|
|
|
|
// server itself.
|
|
|
|
if err := server.Start(); err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to start server: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2017-06-06 01:18:06 +03:00
|
|
|
return err
|
|
|
|
}
|
2018-06-15 06:16:20 +03:00
|
|
|
defer server.Stop()
|
2017-06-06 01:18:06 +03:00
|
|
|
|
2017-08-11 07:40:15 +03:00
|
|
|
// Now that the server has started, if the autopilot mode is currently
|
2018-12-13 14:26:29 +03:00
|
|
|
// active, then we'll start the autopilot agent immediately. It will be
|
|
|
|
// stopped together with the autopilot service.
|
2017-08-11 07:40:15 +03:00
|
|
|
if cfg.Autopilot.Active {
|
2018-12-13 14:26:29 +03:00
|
|
|
if err := atplManager.StartAgent(); err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to start autopilot agent: %v",
|
2017-08-11 07:40:15 +03:00
|
|
|
err)
|
2019-07-18 00:21:19 +03:00
|
|
|
ltndLog.Error(err)
|
2017-08-11 07:40:15 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-06-14 03:31:55 +03:00
|
|
|
if cfg.Watchtower.Active {
|
|
|
|
if err := tower.Start(); err != nil {
|
2019-07-18 00:21:19 +03:00
|
|
|
err := fmt.Errorf("Unable to start watchtower: %v", err)
|
|
|
|
ltndLog.Error(err)
|
2019-06-14 03:31:55 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
defer tower.Stop()
|
|
|
|
}
|
|
|
|
|
2016-03-23 04:50:11 +03:00
|
|
|
// Wait for shutdown signal from either a graceful server stop or from
|
|
|
|
// the interrupt handler.
|
2018-06-15 06:16:20 +03:00
|
|
|
<-signal.ShutdownChannel()
|
2016-07-13 03:03:29 +03:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2019-01-30 11:09:57 +03:00
|
|
|
// getTLSConfig returns a TLS configuration for the gRPC server and credentials
|
|
|
|
// and a proxy destination for the REST reverse proxy.
|
2019-07-22 10:26:25 +03:00
|
|
|
func getTLSConfig(tlsCertPath string, tlsKeyPath string, tlsExtraIPs,
|
|
|
|
tlsExtraDomains []string, rpcListeners []net.Addr) (*tls.Config,
|
2019-06-23 07:07:10 +03:00
|
|
|
*credentials.TransportCredentials, string, error) {
|
2019-01-30 11:09:57 +03:00
|
|
|
|
|
|
|
// Ensure we create TLS key and certificate if they don't exist
|
2019-06-23 07:07:10 +03:00
|
|
|
if !fileExists(tlsCertPath) && !fileExists(tlsKeyPath) {
|
2019-07-22 10:26:25 +03:00
|
|
|
err := genCertPair(
|
|
|
|
tlsCertPath, tlsKeyPath, tlsExtraIPs, tlsExtraDomains,
|
|
|
|
)
|
2019-01-30 11:09:57 +03:00
|
|
|
if err != nil {
|
|
|
|
return nil, nil, "", err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-06-23 07:07:10 +03:00
|
|
|
certData, err := tls.LoadX509KeyPair(tlsCertPath, tlsKeyPath)
|
2019-01-30 11:09:57 +03:00
|
|
|
if err != nil {
|
|
|
|
return nil, nil, "", err
|
|
|
|
}
|
|
|
|
|
2019-04-25 10:09:45 +03:00
|
|
|
cert, err := x509.ParseCertificate(certData.Certificate[0])
|
|
|
|
if err != nil {
|
|
|
|
return nil, nil, "", err
|
|
|
|
}
|
|
|
|
|
|
|
|
// If the certificate expired, delete it and the TLS key and generate a new pair
|
|
|
|
if time.Now().After(cert.NotAfter) {
|
|
|
|
ltndLog.Info("TLS certificate is expired, generating a new one")
|
|
|
|
|
2019-06-23 07:07:10 +03:00
|
|
|
err := os.Remove(tlsCertPath)
|
2019-04-25 10:09:45 +03:00
|
|
|
if err != nil {
|
|
|
|
return nil, nil, "", err
|
|
|
|
}
|
|
|
|
|
2019-06-23 07:07:10 +03:00
|
|
|
err = os.Remove(tlsKeyPath)
|
2019-04-25 10:09:45 +03:00
|
|
|
if err != nil {
|
|
|
|
return nil, nil, "", err
|
|
|
|
}
|
|
|
|
|
2019-07-22 10:26:25 +03:00
|
|
|
err = genCertPair(
|
|
|
|
tlsCertPath, tlsKeyPath, tlsExtraIPs, tlsExtraDomains,
|
|
|
|
)
|
2019-04-25 10:09:45 +03:00
|
|
|
if err != nil {
|
|
|
|
return nil, nil, "", err
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|
|
|
|
|
2019-01-30 11:09:57 +03:00
|
|
|
tlsCfg := &tls.Config{
|
2019-04-25 10:09:45 +03:00
|
|
|
Certificates: []tls.Certificate{certData},
|
2019-01-30 11:09:57 +03:00
|
|
|
CipherSuites: tlsCipherSuites,
|
|
|
|
MinVersion: tls.VersionTLS12,
|
|
|
|
}
|
|
|
|
|
2019-06-23 07:07:10 +03:00
|
|
|
restCreds, err := credentials.NewClientTLSFromFile(tlsCertPath, "")
|
2019-01-30 11:09:57 +03:00
|
|
|
if err != nil {
|
|
|
|
return nil, nil, "", err
|
|
|
|
}
|
|
|
|
|
2019-06-23 07:07:10 +03:00
|
|
|
restProxyDest := rpcListeners[0].String()
|
2019-01-30 11:09:57 +03:00
|
|
|
switch {
|
|
|
|
case strings.Contains(restProxyDest, "0.0.0.0"):
|
|
|
|
restProxyDest = strings.Replace(
|
|
|
|
restProxyDest, "0.0.0.0", "127.0.0.1", 1,
|
|
|
|
)
|
|
|
|
|
|
|
|
case strings.Contains(restProxyDest, "[::]"):
|
|
|
|
restProxyDest = strings.Replace(
|
|
|
|
restProxyDest, "[::]", "[::1]", 1,
|
|
|
|
)
|
|
|
|
}
|
|
|
|
|
|
|
|
return tlsCfg, &restCreds, restProxyDest, nil
|
|
|
|
}
|
|
|
|
|
2017-07-26 02:22:06 +03:00
|
|
|
// fileExists reports whether the named file or directory exists.
|
|
|
|
// This function is taken from https://github.com/btcsuite/btcd
|
|
|
|
func fileExists(name string) bool {
|
|
|
|
if _, err := os.Stat(name); err != nil {
|
|
|
|
if os.IsNotExist(err) {
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
2017-08-14 23:54:06 +03:00
|
|
|
// genCertPair generates a key/cert pair to the paths provided. The
|
|
|
|
// auto-generated certificates should *not* be used in production for public
|
|
|
|
// access as they're self-signed and don't necessarily contain all of the
|
|
|
|
// desired hostnames for the service. For production/public use, consider a
|
|
|
|
// real PKI.
|
|
|
|
//
|
|
|
|
// This function is adapted from https://github.com/btcsuite/btcd and
|
|
|
|
// https://github.com/btcsuite/btcutil
|
2019-07-22 10:26:25 +03:00
|
|
|
func genCertPair(certFile, keyFile string, tlsExtraIPs,
|
|
|
|
tlsExtraDomains []string) error {
|
|
|
|
|
2017-07-26 02:22:06 +03:00
|
|
|
rpcsLog.Infof("Generating TLS certificates...")
|
|
|
|
|
|
|
|
org := "lnd autogenerated cert"
|
2017-08-14 23:54:06 +03:00
|
|
|
now := time.Now()
|
|
|
|
validUntil := now.Add(autogenCertValidity)
|
|
|
|
|
|
|
|
// Check that the certificate validity isn't past the ASN.1 end of time.
|
|
|
|
if validUntil.After(endOfTime) {
|
|
|
|
validUntil = endOfTime
|
|
|
|
}
|
|
|
|
|
|
|
|
// Generate a serial number that's below the serialNumberLimit.
|
|
|
|
serialNumber, err := rand.Int(rand.Reader, serialNumberLimit)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("failed to generate serial number: %s", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Collect the host's IP addresses, including loopback, in a slice.
|
|
|
|
ipAddresses := []net.IP{net.ParseIP("127.0.0.1"), net.ParseIP("::1")}
|
|
|
|
|
|
|
|
// addIP appends an IP address only if it isn't already in the slice.
|
|
|
|
addIP := func(ipAddr net.IP) {
|
|
|
|
for _, ip := range ipAddresses {
|
|
|
|
if bytes.Equal(ip, ipAddr) {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
}
|
|
|
|
ipAddresses = append(ipAddresses, ipAddr)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Add all the interface IPs that aren't already in the slice.
|
|
|
|
addrs, err := net.InterfaceAddrs()
|
2017-07-26 02:22:06 +03:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2017-08-14 23:54:06 +03:00
|
|
|
for _, a := range addrs {
|
|
|
|
ipAddr, _, err := net.ParseCIDR(a.String())
|
|
|
|
if err == nil {
|
|
|
|
addIP(ipAddr)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-07-22 10:26:25 +03:00
|
|
|
// Add extra IPs to the slice.
|
|
|
|
for _, ip := range tlsExtraIPs {
|
|
|
|
ipAddr := net.ParseIP(ip)
|
|
|
|
if ipAddr != nil {
|
|
|
|
addIP(ipAddr)
|
2019-02-26 07:21:46 +03:00
|
|
|
}
|
2018-01-10 22:48:21 +03:00
|
|
|
}
|
|
|
|
|
2017-08-14 23:54:06 +03:00
|
|
|
// Collect the host's names into a slice.
|
|
|
|
host, err := os.Hostname()
|
|
|
|
if err != nil {
|
2019-01-24 16:51:05 +03:00
|
|
|
rpcsLog.Errorf("Failed getting hostname, falling back to "+
|
|
|
|
"localhost: %v", err)
|
|
|
|
host = "localhost"
|
2017-08-14 23:54:06 +03:00
|
|
|
}
|
2019-01-24 16:51:05 +03:00
|
|
|
|
2017-08-14 23:54:06 +03:00
|
|
|
dnsNames := []string{host}
|
|
|
|
if host != "localhost" {
|
|
|
|
dnsNames = append(dnsNames, "localhost")
|
|
|
|
}
|
2019-07-22 10:26:25 +03:00
|
|
|
dnsNames = append(dnsNames, tlsExtraDomains...)
|
2017-08-14 23:54:06 +03:00
|
|
|
|
2018-05-23 16:38:19 +03:00
|
|
|
// Also add fake hostnames for unix sockets, otherwise hostname
|
|
|
|
// verification will fail in the client.
|
|
|
|
dnsNames = append(dnsNames, "unix", "unixpacket")
|
|
|
|
|
2017-08-14 23:54:06 +03:00
|
|
|
// Generate a private key for the certificate.
|
2018-02-24 05:24:23 +03:00
|
|
|
priv, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
|
2017-08-14 23:54:06 +03:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
// Construct the certificate template.
|
|
|
|
template := x509.Certificate{
|
|
|
|
SerialNumber: serialNumber,
|
|
|
|
Subject: pkix.Name{
|
|
|
|
Organization: []string{org},
|
|
|
|
CommonName: host,
|
|
|
|
},
|
|
|
|
NotBefore: now.Add(-time.Hour * 24),
|
|
|
|
NotAfter: validUntil,
|
|
|
|
|
|
|
|
KeyUsage: x509.KeyUsageKeyEncipherment |
|
|
|
|
x509.KeyUsageDigitalSignature | x509.KeyUsageCertSign,
|
2018-10-07 05:34:32 +03:00
|
|
|
IsCA: true, // so can sign self.
|
2017-08-14 23:54:06 +03:00
|
|
|
BasicConstraintsValid: true,
|
|
|
|
|
|
|
|
DNSNames: dnsNames,
|
|
|
|
IPAddresses: ipAddresses,
|
|
|
|
}
|
|
|
|
|
|
|
|
derBytes, err := x509.CreateCertificate(rand.Reader, &template,
|
|
|
|
&template, &priv.PublicKey, priv)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("failed to create certificate: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
certBuf := &bytes.Buffer{}
|
|
|
|
err = pem.Encode(certBuf, &pem.Block{Type: "CERTIFICATE",
|
|
|
|
Bytes: derBytes})
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("failed to encode certificate: %v", err)
|
|
|
|
}
|
|
|
|
|
2018-02-24 05:24:23 +03:00
|
|
|
keybytes, err := x509.MarshalECPrivateKey(priv)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("unable to encode privkey: %v", err)
|
|
|
|
}
|
2017-08-14 23:54:06 +03:00
|
|
|
keyBuf := &bytes.Buffer{}
|
2018-02-24 05:24:23 +03:00
|
|
|
err = pem.Encode(keyBuf, &pem.Block{Type: "EC PRIVATE KEY",
|
2017-08-14 23:54:06 +03:00
|
|
|
Bytes: keybytes})
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("failed to encode private key: %v", err)
|
|
|
|
}
|
2017-07-26 02:22:06 +03:00
|
|
|
|
|
|
|
// Write cert and key files.
|
2017-08-14 23:54:06 +03:00
|
|
|
if err = ioutil.WriteFile(certFile, certBuf.Bytes(), 0644); err != nil {
|
2017-07-26 02:22:06 +03:00
|
|
|
return err
|
|
|
|
}
|
2017-08-14 23:54:06 +03:00
|
|
|
if err = ioutil.WriteFile(keyFile, keyBuf.Bytes(), 0600); err != nil {
|
2017-07-26 02:22:06 +03:00
|
|
|
os.Remove(certFile)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
rpcsLog.Infof("Done generating TLS certificates")
|
|
|
|
return nil
|
|
|
|
}
|
2017-08-18 04:50:57 +03:00
|
|
|
|
lnd+rpc: modify rpcServer to fully manaage listeners and gRPC, handle sub-servers
In this commit, we modify the existing rpcServer to fully manage the
macaroons, gRPC server, and also seek out and create all sub-servers.
With this change, the RPC server gains more responsibility, as it
becomes the "root" server in the hierarchy of gRPC sub-servers.
In addition to creating each sub-server, it will also merge the set of
macaroon permissions for each sub-server, with the permissions of the
rest of the RPC infra. As a result, each sub-server is able to
independently specify what it needs w.r.t macaroon permissions and have
that taken care of by the RPC server. In order to achieve this, we need
to unify the creation of the RPC interceptors, and also fully manage the
gRPC server ourselves.
Some examples with various build configs:
```
⛰i make build
Building debug lnd and lncli.
go build -v -tags="dev" -o lnd-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd
go build -v -tags="dev" -o lncli-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd/cmd/lncli
⛰i ./lnd-debug --debuglevel=debug --signrpc.signermacaroonpath=~/sign.macaroon
unknown flag `signrpc.signermacaroonpath'
unknown flag `signrpc.signermacaroonpath'
⛰i make build tags=signerrpc
Building debug lnd and lncli.
go build -v -tags="dev signerrpc" -o lnd-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd
go build -v -tags="dev signerrpc" -o lncli-debug -ldflags "-X github.com/lightningnetwork/lnd/build.Commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty" github.com/lightningnetwork/lnd/cmd/lncli
⛰i ./lnd-debug --debuglevel=debug --signrpc.signermacaroonpath=~/sign.macaroon
2018-10-22 17:31:01.132 [INF] LTND: Version: 0.5.0-beta commit=v0.5-beta-143-gb2069914c4b76109b7c59320dc48f8a5f30deb75-dirty, build=development, logging=default
2018-10-22 17:31:01.133 [INF] LTND: Active chain: Bitcoin (network=simnet)
2018-10-22 17:31:01.140 [INF] CHDB: Checking for schema update: latest_version=6, db_version=6
2018-10-22 17:31:01.236 [INF] LTND: Primary chain is set to: bitcoin
2018-10-22 17:31:02.391 [INF] LNWL: Opened wallet
2018-10-22 17:31:03.315 [INF] LNWL: The wallet has been unlocked without a time limit
2018-10-22 17:31:03.315 [INF] LTND: LightningWallet opened
2018-10-22 17:31:03.319 [INF] LNWL: Catching up block hashes to height 3060, this will take a while...
2018-10-22 17:31:03.320 [INF] HSWC: Restoring in-memory circuit state from disk
2018-10-22 17:31:03.320 [INF] LNWL: Done catching up block hashes
2018-10-22 17:31:03.320 [INF] HSWC: Payment circuits loaded: num_pending=0, num_open=0
2018-10-22 17:31:03.322 [DBG] LTND: Populating dependencies for sub RPC server: Signrpc
```
As for the config, an example is:
```
[signrpc]
signrpc.signermacaroonpath=~/signer.macaroon
```
2018-10-23 04:03:07 +03:00
|
|
|
// genMacaroons generates three macaroon files; one admin-level, one for
|
|
|
|
// invoice access and one read-only. These can also be used to generate more
|
|
|
|
// granular macaroons.
|
2018-03-21 02:50:08 +03:00
|
|
|
func genMacaroons(ctx context.Context, svc *macaroons.Service,
|
|
|
|
admFile, roFile, invoiceFile string) error {
|
|
|
|
|
|
|
|
// First, we'll generate a macaroon that only allows the caller to
|
|
|
|
// access invoice related calls. This is useful for merchants and other
|
|
|
|
// services to allow an isolated instance that can only query and
|
|
|
|
// modify invoices.
|
|
|
|
invoiceMac, err := svc.Oven.NewMacaroon(
|
|
|
|
ctx, bakery.LatestVersion, nil, invoicePermissions...,
|
|
|
|
)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
invoiceMacBytes, err := invoiceMac.M().MarshalBinary()
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
err = ioutil.WriteFile(invoiceFile, invoiceMacBytes, 0644)
|
|
|
|
if err != nil {
|
|
|
|
os.Remove(invoiceFile)
|
|
|
|
return err
|
|
|
|
}
|
2018-01-16 19:18:41 +03:00
|
|
|
|
|
|
|
// Generate the read-only macaroon and write it to a file.
|
2018-03-21 02:50:08 +03:00
|
|
|
roMacaroon, err := svc.Oven.NewMacaroon(
|
|
|
|
ctx, bakery.LatestVersion, nil, readPermissions...,
|
|
|
|
)
|
2017-08-18 04:50:57 +03:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2018-01-16 19:18:41 +03:00
|
|
|
roBytes, err := roMacaroon.M().MarshalBinary()
|
2017-08-18 04:50:57 +03:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2018-01-16 19:18:41 +03:00
|
|
|
if err = ioutil.WriteFile(roFile, roBytes, 0644); err != nil {
|
|
|
|
os.Remove(admFile)
|
2017-08-18 04:50:57 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2018-01-16 19:18:41 +03:00
|
|
|
// Generate the admin macaroon and write it to a file.
|
2018-03-21 02:50:08 +03:00
|
|
|
adminPermissions := append(readPermissions, writePermissions...)
|
|
|
|
admMacaroon, err := svc.Oven.NewMacaroon(
|
|
|
|
ctx, bakery.LatestVersion, nil, adminPermissions...,
|
|
|
|
)
|
2017-09-13 23:44:05 +03:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2018-01-16 19:18:41 +03:00
|
|
|
admBytes, err := admMacaroon.M().MarshalBinary()
|
2017-08-18 04:50:57 +03:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2018-01-16 19:18:41 +03:00
|
|
|
if err = ioutil.WriteFile(admFile, admBytes, 0600); err != nil {
|
2017-08-18 04:50:57 +03:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
2017-10-12 12:37:37 +03:00
|
|
|
|
2018-03-27 00:12:17 +03:00
|
|
|
// WalletUnlockParams holds the variables used to parameterize the unlocking of
|
|
|
|
// lnd's wallet after it has already been created.
|
|
|
|
type WalletUnlockParams struct {
|
|
|
|
// Password is the public and private wallet passphrase.
|
|
|
|
Password []byte
|
|
|
|
|
|
|
|
// Birthday specifies the approximate time that this wallet was created.
|
|
|
|
// This is used to bound any rescans on startup.
|
|
|
|
Birthday time.Time
|
|
|
|
|
|
|
|
// RecoveryWindow specifies the address lookahead when entering recovery
|
|
|
|
// mode. A recovery will be attempted if this value is non-zero.
|
|
|
|
RecoveryWindow uint32
|
2018-05-22 10:31:02 +03:00
|
|
|
|
|
|
|
// Wallet is the loaded and unlocked Wallet. This is returned
|
|
|
|
// from the unlocker service to avoid it being unlocked twice (once in
|
|
|
|
// the unlocker service to check if the password is correct and again
|
|
|
|
// later when lnd actually uses it). Because unlocking involves scrypt
|
|
|
|
// which is resource intensive, we want to avoid doing it twice.
|
|
|
|
Wallet *wallet.Wallet
|
2018-12-10 07:08:32 +03:00
|
|
|
|
|
|
|
// ChansToRestore a set of static channel backups that should be
|
|
|
|
// restored before the main server instance starts up.
|
|
|
|
ChansToRestore walletunlocker.ChannelsToRecover
|
2018-03-27 00:12:17 +03:00
|
|
|
}
|
|
|
|
|
2017-10-12 12:37:37 +03:00
|
|
|
// waitForWalletPassword will spin up gRPC and REST endpoints for the
|
|
|
|
// WalletUnlocker server, and block until a password is provided by
|
|
|
|
// the user to this RPC server.
|
2019-07-09 12:09:19 +03:00
|
|
|
func waitForWalletPassword(restEndpoints []net.Addr,
|
|
|
|
restDialOpts []grpc.DialOption, restProxyDest string,
|
|
|
|
tlsConf *tls.Config, getListeners rpcListeners) (
|
|
|
|
*WalletUnlockParams, error) {
|
|
|
|
|
|
|
|
// Start a gRPC server listening for HTTP/2 connections, solely used
|
|
|
|
// for getting the encryption password from the client.
|
|
|
|
listeners, cleanup, serverOpts, err := getListeners()
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
defer cleanup()
|
2017-10-20 05:53:19 +03:00
|
|
|
|
2018-04-20 10:14:41 +03:00
|
|
|
// Set up a new PasswordService, which will listen for passwords
|
|
|
|
// provided over RPC.
|
2017-10-12 12:37:37 +03:00
|
|
|
grpcServer := grpc.NewServer(serverOpts...)
|
2019-05-08 23:07:26 +03:00
|
|
|
defer grpcServer.GracefulStop()
|
2017-10-12 12:37:37 +03:00
|
|
|
|
|
|
|
chainConfig := cfg.Bitcoin
|
|
|
|
if registeredChains.PrimaryChain() == litecoinChain {
|
|
|
|
chainConfig = cfg.Litecoin
|
|
|
|
}
|
2018-04-20 10:14:41 +03:00
|
|
|
|
|
|
|
// The macaroon files are passed to the wallet unlocker since they are
|
|
|
|
// also encrypted with the wallet's password. These files will be
|
|
|
|
// deleted within it and recreated when successfully changing the
|
|
|
|
// wallet's password.
|
|
|
|
macaroonFiles := []string{
|
2018-08-22 22:27:16 +03:00
|
|
|
filepath.Join(networkDir, macaroons.DBFilename),
|
2018-04-20 10:14:41 +03:00
|
|
|
cfg.AdminMacPath, cfg.ReadMacPath, cfg.InvoiceMacPath,
|
|
|
|
}
|
2018-04-20 10:06:06 +03:00
|
|
|
pwService := walletunlocker.New(
|
2018-04-20 10:14:41 +03:00
|
|
|
chainConfig.ChainDir, activeNetParams.Params, macaroonFiles,
|
2018-04-20 10:06:06 +03:00
|
|
|
)
|
2017-10-12 12:37:37 +03:00
|
|
|
lnrpc.RegisterWalletUnlockerServer(grpcServer, pwService)
|
|
|
|
|
2017-12-17 20:28:38 +03:00
|
|
|
// Use a WaitGroup so we can be sure the instructions on how to input the
|
|
|
|
// password is the last thing to be printed to the console.
|
|
|
|
var wg sync.WaitGroup
|
2017-10-12 12:37:37 +03:00
|
|
|
|
2019-07-09 12:09:19 +03:00
|
|
|
for _, lis := range listeners {
|
2017-12-17 20:28:38 +03:00
|
|
|
wg.Add(1)
|
2019-07-09 12:09:19 +03:00
|
|
|
go func(lis net.Listener) {
|
|
|
|
rpcsLog.Infof("password RPC server listening on %s",
|
|
|
|
lis.Addr())
|
2017-12-17 20:28:38 +03:00
|
|
|
wg.Done()
|
|
|
|
grpcServer.Serve(lis)
|
2019-07-09 12:09:19 +03:00
|
|
|
}(lis)
|
2017-12-17 20:28:38 +03:00
|
|
|
}
|
2017-10-12 12:37:37 +03:00
|
|
|
|
|
|
|
// Start a REST proxy for our gRPC server above.
|
|
|
|
ctx := context.Background()
|
|
|
|
ctx, cancel := context.WithCancel(ctx)
|
|
|
|
defer cancel()
|
|
|
|
|
|
|
|
mux := proxy.NewServeMux()
|
2017-12-17 20:28:38 +03:00
|
|
|
|
2019-07-09 12:09:19 +03:00
|
|
|
err = lnrpc.RegisterWalletUnlockerHandlerFromEndpoint(
|
2019-01-30 11:09:57 +03:00
|
|
|
ctx, mux, restProxyDest, restDialOpts,
|
2018-05-23 16:38:19 +03:00
|
|
|
)
|
2017-10-12 12:37:37 +03:00
|
|
|
if err != nil {
|
2018-03-27 00:12:17 +03:00
|
|
|
return nil, err
|
2017-10-12 12:37:37 +03:00
|
|
|
}
|
2017-12-17 20:28:38 +03:00
|
|
|
|
2017-10-12 12:37:37 +03:00
|
|
|
srv := &http.Server{Handler: mux}
|
|
|
|
|
2017-12-17 20:28:38 +03:00
|
|
|
for _, restEndpoint := range restEndpoints {
|
2018-07-31 11:29:12 +03:00
|
|
|
lis, err := lncfg.TLSListenOnAddress(restEndpoint, tlsConf)
|
2017-10-12 12:37:37 +03:00
|
|
|
if err != nil {
|
2018-05-23 16:38:19 +03:00
|
|
|
ltndLog.Errorf(
|
|
|
|
"password gRPC proxy unable to listen on %s",
|
|
|
|
restEndpoint,
|
|
|
|
)
|
2018-03-27 00:12:17 +03:00
|
|
|
return nil, err
|
2017-10-12 12:37:37 +03:00
|
|
|
}
|
2017-12-17 20:28:38 +03:00
|
|
|
defer lis.Close()
|
|
|
|
|
|
|
|
wg.Add(1)
|
|
|
|
go func() {
|
2018-05-23 16:38:19 +03:00
|
|
|
rpcsLog.Infof(
|
|
|
|
"password gRPC proxy started at %s",
|
|
|
|
lis.Addr(),
|
|
|
|
)
|
2017-12-17 20:28:38 +03:00
|
|
|
wg.Done()
|
|
|
|
srv.Serve(lis)
|
|
|
|
}()
|
|
|
|
}
|
|
|
|
|
|
|
|
// Wait for gRPC and REST servers to be up running.
|
|
|
|
wg.Wait()
|
2017-10-12 12:37:37 +03:00
|
|
|
|
|
|
|
// Wait for user to provide the password.
|
2018-04-20 10:14:41 +03:00
|
|
|
ltndLog.Infof("Waiting for wallet encryption password. Use `lncli " +
|
|
|
|
"create` to create a wallet, `lncli unlock` to unlock an " +
|
|
|
|
"existing wallet, or `lncli changepassword` to change the " +
|
|
|
|
"password of an existing wallet and unlock it.")
|
2017-10-12 12:37:37 +03:00
|
|
|
|
2018-02-02 07:49:34 +03:00
|
|
|
// We currently don't distinguish between getting a password to be used
|
|
|
|
// for creation or unlocking, as a new wallet db will be created if
|
|
|
|
// none exists when creating the chain control.
|
2017-10-12 12:37:37 +03:00
|
|
|
select {
|
2018-02-02 07:49:34 +03:00
|
|
|
|
|
|
|
// The wallet is being created for the first time, we'll check to see
|
|
|
|
// if the user provided any entropy for seed creation. If so, then
|
|
|
|
// we'll create the wallet early to load the seed.
|
|
|
|
case initMsg := <-pwService.InitMsgs:
|
|
|
|
password := initMsg.Passphrase
|
|
|
|
cipherSeed := initMsg.WalletSeed
|
2018-03-27 00:12:17 +03:00
|
|
|
recoveryWindow := initMsg.RecoveryWindow
|
2018-02-02 07:49:34 +03:00
|
|
|
|
2018-03-06 19:55:10 +03:00
|
|
|
// Before we proceed, we'll check the internal version of the
|
|
|
|
// seed. If it's greater than the current key derivation
|
|
|
|
// version, then we'll return an error as we don't understand
|
|
|
|
// this.
|
|
|
|
if cipherSeed.InternalVersion != keychain.KeyDerivationVersion {
|
2018-03-27 00:12:17 +03:00
|
|
|
return nil, fmt.Errorf("invalid internal seed version "+
|
|
|
|
"%v, current version is %v",
|
2018-03-06 19:55:10 +03:00
|
|
|
cipherSeed.InternalVersion,
|
|
|
|
keychain.KeyDerivationVersion)
|
|
|
|
}
|
|
|
|
|
2018-02-02 07:49:34 +03:00
|
|
|
netDir := btcwallet.NetworkDir(
|
|
|
|
chainConfig.ChainDir, activeNetParams.Params,
|
|
|
|
)
|
2018-03-27 00:12:17 +03:00
|
|
|
loader := wallet.NewLoader(
|
|
|
|
activeNetParams.Params, netDir, uint32(recoveryWindow),
|
|
|
|
)
|
2018-02-02 07:49:34 +03:00
|
|
|
|
|
|
|
// With the seed, we can now use the wallet loader to create
|
2018-05-22 10:31:02 +03:00
|
|
|
// the wallet, then pass it back to avoid unlocking it again.
|
2018-03-27 00:12:17 +03:00
|
|
|
birthday := cipherSeed.BirthdayTime()
|
2018-05-22 10:31:02 +03:00
|
|
|
newWallet, err := loader.CreateNewWallet(
|
2018-03-27 00:12:17 +03:00
|
|
|
password, password, cipherSeed.Entropy[:], birthday,
|
2018-02-02 07:49:34 +03:00
|
|
|
)
|
|
|
|
if err != nil {
|
2018-05-22 10:31:02 +03:00
|
|
|
// Don't leave the file open in case the new wallet
|
|
|
|
// could not be created for whatever reason.
|
|
|
|
if err := loader.UnloadWallet(); err != nil {
|
2018-06-15 06:16:20 +03:00
|
|
|
ltndLog.Errorf("Could not unload new "+
|
2018-05-22 10:31:02 +03:00
|
|
|
"wallet: %v", err)
|
|
|
|
}
|
2018-03-27 00:12:17 +03:00
|
|
|
return nil, err
|
2018-02-02 07:49:34 +03:00
|
|
|
}
|
|
|
|
|
2018-12-10 07:08:32 +03:00
|
|
|
return &WalletUnlockParams{
|
2018-03-27 00:12:17 +03:00
|
|
|
Password: password,
|
|
|
|
Birthday: birthday,
|
|
|
|
RecoveryWindow: recoveryWindow,
|
2018-05-22 10:31:02 +03:00
|
|
|
Wallet: newWallet,
|
2018-12-10 07:08:32 +03:00
|
|
|
ChansToRestore: initMsg.ChanBackups,
|
|
|
|
}, nil
|
2018-02-02 07:49:34 +03:00
|
|
|
|
|
|
|
// The wallet has already been created in the past, and is simply being
|
|
|
|
// unlocked. So we'll just return these passphrases.
|
2018-03-27 00:12:17 +03:00
|
|
|
case unlockMsg := <-pwService.UnlockMsgs:
|
2018-12-10 07:08:32 +03:00
|
|
|
return &WalletUnlockParams{
|
2018-03-27 00:12:17 +03:00
|
|
|
Password: unlockMsg.Passphrase,
|
|
|
|
RecoveryWindow: unlockMsg.RecoveryWindow,
|
2018-05-22 10:31:02 +03:00
|
|
|
Wallet: unlockMsg.Wallet,
|
2018-12-10 07:08:32 +03:00
|
|
|
ChansToRestore: unlockMsg.ChanBackups,
|
|
|
|
}, nil
|
2018-02-02 07:49:34 +03:00
|
|
|
|
2018-06-15 06:16:20 +03:00
|
|
|
case <-signal.ShutdownChannel():
|
2018-03-27 00:12:17 +03:00
|
|
|
return nil, fmt.Errorf("shutting down")
|
2017-10-12 12:37:37 +03:00
|
|
|
}
|
|
|
|
}
|