Core Lightning, software program for working Bitcoin Lightning fee nodes, has launched v26.06.9 with safety fixes and a restore for a regression that would delay channel site visitors on busy nodes working v26.06.8.
GitHub lists the brand new launch as printed Oct. 7, whereas its versioned changelog carries an Oct. 6 date.
The replace offers operators who put in v26.06.8 a contemporary resolution on upgrading, following the Sept. 27 revoked-channel penalty flaw that was fastened in v26.06.7. The most recent patch provides fixes and addresses a regression launched by that later model.
Bitcoin fee delays and shutdown threat
In v26.06.8, routine gossip, pings, and onion messages counted towards a CPU price range meant for gossip queries. On busy nodes, that accounting may throttle friends and delay channel site visitors, in keeping with the maintainers.
V26.06.9 reserves that price range for gossip queries, so odd messages not eat it, eradicating the documented explanation for this throttling. The regression described by maintainers issues busy nodes working Core Lightning v26.06.8.
The changelog additionally describes a repair for a fee contract (HTLC) that reaches its deadline whereas a channel is shutting down. V26.06.9 now force-closes the channel in that scenario, stopping forwarded funds from being misplaced if the fee is fulfilled late.
For an operator forwarding funds, this fixes a funds-protection drawback when fee deadlines and channel shutdown overlap.
Different fixes implement the boundaries carried by runes used to authorize calls, so a restricted rune can not create an unrestricted one or relist blacklisted runes. Restrictions on the corresponding creation and blocklisting strategies now additionally cowl the invokerune and destroyrune aliases.
The listconfigs command now masks a number of delicate values, together with restoration data and Bitcoin RPC passwords, for each caller. The setconfig command closes a path for injecting configuration strains by persistent choice values.
The fixes can be found instantly, however maintainers have quickly held again safety exams to make exploit improvement tougher and provides operators extra time to improve.
Nodes which have run grasp can not downgrade to a 26.06.x launch as a result of their database schema is newer. The discharge additionally reiterates that twin funding stays experimental and discourages zero-confirmation channels with untrusted friends.
Maintainers urge Core Lightning customers, together with these on v26.06.8, to improve to v26.06.9 as quickly as sensible.

