packages feed

ppad-bolt3-0.1.0: CHANGELOG

# Changelog

- 0.1.0 (2026-10-10)
  * A substantial rewrite, with breaking changes throughout:

    * Ports to ppad-bolt1 0.1.0 and ppad-tx 0.2.0. Amounts, points,
      hashes and per-commitment secrets are bolt1's types (amounts are
      bounded, with checked arithmetic); bolt3's Pubkey is merged into
      bolt1's Point, wrapped in role newtypes (RevocationPubkey, etc.).

    * The API is exported from Lightning.Protocol.BOLT3 alone, with
      snake_case names. Types with invariants (CommitmentNumber,
      SecretIndex, Seed, Seckey, SecretStore) are abstract, and every
      type has an NFData instance.

    * ChannelFeatures is replaced by CommitmentFormat (StaticRemotekey
      or Anchors).

    * CommitmentContext is owner-relative throughout: the payment
      basepoints are ordered for the obscured commitment number by
      cc_is_funder. build_commitment_tx fails rather than produce a
      transaction without outputs.

    * OutputType carries the HTLC an output pays. build_htlc_tx replaces
      build_htlc_timeout_tx and build_htlc_success_tx, choosing by HTLC
      direction, and fails if the fee exceeds the amount.

    * Closing transactions have separate builders with spec-shaped
      inputs: build_legacy_closing_tx applies the signer's dust limit to
      both outputs and can omit the signer's output; build_closing_tx
      (option_simple_close) charges the closer, takes an explicit choice
      of outputs, and gives OP_RETURN outputs amount zero.

    * to_remote_script is split into to_remote_witness_script and
      to_remote_script_pubkey. Witness functions append the witness
      script and take typed keys; funding_witness orders signatures by
      pubkey. Adds htlc_success_witness, htlc_timeout_witness and
      remote_htlc_sighash.

    * Per-commitment secrets use Seed, SecretIndex and bolt1's
      PerCommitmentSecret. SecretStore is abstract, with a redacted
      Show instance and secret_store/un_secret_store for persistence.
      Adds commitment_secret_index.

    * Adds derive_commitment_keys, derive_privkey and
      derive_revocationprivkey.

    * Renames encode_tx to encode_commitment_tx, and documents the
      encoders as producing unsigned, witness-free serializations.

    * Removes the Validate, Decode, Encode and Internal modules, the
      role-specific key derivation functions, encode_tx_for_signing,
      encode_witness, encode_funding_witness, has_anchors, sort_outputs,
      trimmed_htlcs, untrimmed_htlcs, derive_secret, the HTLC output
      script aliases, the weight constants and unused record fields.

  * Fixes insert_secret, which discarded the entries needed to derive
    older secrets and accepted invalid secret sequences.

  * Fixes closing transactions, which used each party's dust limit in
    legacy closes, and charged the funder and paid OP_RETURN outputs in
    option_simple_close.

  * Rejects key derivations yielding the point at infinity.

  * Tests cover every BOLT #3 Appendix B-F vector.

- 0.0.1 (2026-04-18)
  * Initial release.