diff --git a/src/builder.rs b/src/builder.rs index 1158044e4..5179a5899 100644 --- a/src/builder.rs +++ b/src/builder.rs @@ -2391,6 +2391,7 @@ fn build_with_store_internal( let connection_manager = Arc::new(ConnectionManager::new( Arc::clone(&peer_manager), + config.disable_outbound_lightning_connections, config.tor_config.clone(), Arc::clone(&keys_manager), Arc::clone(&logger), diff --git a/src/config.rs b/src/config.rs index cb74b55c8..21aabb2d7 100644 --- a/src/config.rs +++ b/src/config.rs @@ -203,6 +203,7 @@ impl Default for ForwardedPaymentTrackingMode { /// |----------------------------------------|--------------------------------------| /// | `storage_dir_path` | /tmp/ldk_node/ | /// | `network` | Bitcoin | +/// |`disable_outbound_lightning_connections`| false | /// | `listening_addresses` | None | /// | `announcement_addresses` | None | /// | `node_alias` | None | @@ -227,6 +228,12 @@ pub struct Config { pub storage_dir_path: String, /// The used Bitcoin network. pub network: Network, + /// Disables all outbound Lightning peer-to-peer (P2P) connections. + /// + /// Inbound connections are controlled separately by + /// [`Config::listening_addresses`]; set it to `None` to prevent inbound connections as well. + /// Other networking, including chain synchronization, is unaffected. + pub disable_outbound_lightning_connections: bool, /// The addresses on which the node will listen for incoming connections. /// /// **Note**: We will only allow opening and accepting public channels if the `node_alias` and the @@ -304,6 +311,7 @@ impl Default for Config { Self { storage_dir_path: DEFAULT_STORAGE_DIR_PATH.to_string(), network: DEFAULT_NETWORK, + disable_outbound_lightning_connections: false, listening_addresses: None, announcement_addresses: None, trusted_peers_0conf: Vec::new(), diff --git a/src/connection.rs b/src/connection.rs index ccb6f9846..294e9b110 100644 --- a/src/connection.rs +++ b/src/connection.rs @@ -14,7 +14,7 @@ use bitcoin::secp256k1::PublicKey; use lightning::ln::msgs::SocketAddress; use crate::config::TorConfig; -use crate::logger::{log_debug, log_error, log_info, LdkLogger}; +use crate::logger::{log_debug, log_error, log_info, log_warn, LdkLogger}; use crate::types::{KeysManager, PeerManager}; use crate::Error; @@ -57,6 +57,7 @@ where { pending_connections: PendingConnections, peer_manager: Arc, + disable_outbound_lightning_connections: bool, tor_proxy_config: Option, keys_manager: Arc, logger: L, @@ -67,12 +68,19 @@ where L::Target: LdkLogger, { pub(crate) fn new( - peer_manager: Arc, tor_proxy_config: Option, - keys_manager: Arc, logger: L, + peer_manager: Arc, disable_outbound_lightning_connections: bool, + tor_proxy_config: Option, keys_manager: Arc, logger: L, ) -> Self { let pending_connections = Mutex::new(HashMap::new()); - Self { pending_connections, peer_manager, tor_proxy_config, keys_manager, logger } + Self { + pending_connections, + peer_manager, + disable_outbound_lightning_connections, + tor_proxy_config, + keys_manager, + logger, + } } pub(crate) async fn connect_peer_if_necessary( @@ -115,6 +123,11 @@ where async fn do_connect_peer_internal( &self, node_id: PublicKey, addr: SocketAddress, ) -> Result<(), Error> { + if self.disable_outbound_lightning_connections { + log_warn!(self.logger, "Outbound Lightning peer connections are disabled."); + return Err(Error::ConnectionFailed); + } + log_info!(self.logger, "Connecting to peer: {}@{}", node_id, addr); match addr { diff --git a/src/lib.rs b/src/lib.rs index fbb65b000..d67261cd5 100644 --- a/src/lib.rs +++ b/src/lib.rs @@ -1294,6 +1294,8 @@ impl Node { /// Connect to a node on the peer-to-peer network. /// /// If `persist` is set to `true`, we'll remember the peer and reconnect to it on restart. + /// Outbound connection attempts fail with [`Error::ConnectionFailed`] if + /// [`Config::disable_outbound_lightning_connections`] is set. pub fn connect( &self, node_id: PublicKey, address: SocketAddress, persist: bool, ) -> Result<(), Error> {