# Changelog
- 0.1.0 (2026-10-10)
* A substantial rewrite, with breaking changes throughout:
* Ports to ppad-bolt1 0.1.0 and ppad-tx 0.2.0. Amounts, points,
hashes and per-commitment secrets are bolt1's types (amounts are
bounded, with checked arithmetic); bolt3's Pubkey is merged into
bolt1's Point, wrapped in role newtypes (RevocationPubkey, etc.).
* The API is exported from Lightning.Protocol.BOLT3 alone, with
snake_case names. Types with invariants (CommitmentNumber,
SecretIndex, Seed, Seckey, SecretStore) are abstract, and every
type has an NFData instance.
* ChannelFeatures is replaced by CommitmentFormat (StaticRemotekey
or Anchors).
* CommitmentContext is owner-relative throughout: the payment
basepoints are ordered for the obscured commitment number by
cc_is_funder. build_commitment_tx fails rather than produce a
transaction without outputs.
* OutputType carries the HTLC an output pays. build_htlc_tx replaces
build_htlc_timeout_tx and build_htlc_success_tx, choosing by HTLC
direction, and fails if the fee exceeds the amount.
* Closing transactions have separate builders with spec-shaped
inputs: build_legacy_closing_tx applies the signer's dust limit to
both outputs and can omit the signer's output; build_closing_tx
(option_simple_close) charges the closer, takes an explicit choice
of outputs, and gives OP_RETURN outputs amount zero.
* to_remote_script is split into to_remote_witness_script and
to_remote_script_pubkey. Witness functions append the witness
script and take typed keys; funding_witness orders signatures by
pubkey. Adds htlc_success_witness, htlc_timeout_witness and
remote_htlc_sighash.
* Per-commitment secrets use Seed, SecretIndex and bolt1's
PerCommitmentSecret. SecretStore is abstract, with a redacted
Show instance and secret_store/un_secret_store for persistence.
Adds commitment_secret_index.
* Adds derive_commitment_keys, derive_privkey and
derive_revocationprivkey.
* Renames encode_tx to encode_commitment_tx, and documents the
encoders as producing unsigned, witness-free serializations.
* Removes the Validate, Decode, Encode and Internal modules, the
role-specific key derivation functions, encode_tx_for_signing,
encode_witness, encode_funding_witness, has_anchors, sort_outputs,
trimmed_htlcs, untrimmed_htlcs, derive_secret, the HTLC output
script aliases, the weight constants and unused record fields.
* Fixes insert_secret, which discarded the entries needed to derive
older secrets and accepted invalid secret sequences.
* Fixes closing transactions, which used each party's dust limit in
legacy closes, and charged the funder and paid OP_RETURN outputs in
option_simple_close.
* Rejects key derivations yielding the point at infinity.
* Tests cover every BOLT #3 Appendix B-F vector.
- 0.0.1 (2026-04-18)
* Initial release.