# Changelog
- 0.1.0 (2026-10-10)
* A substantial rewrite, with breaking changes throughout:
* The API is exported from Lightning.Protocol.BOLT4 alone, and uses
snake_case names (e.g. construct, process, construct_error,
create_blinded_path). The Prim, Codec and Internal modules are
no longer exposed.
* Fundamental types come from ppad-bolt1: points are Points,
amounts are MilliSatoshis, short channel ids and TLV streams are
bolt1's. allowed_features is a ppad-bolt9 FeatureVector. The
private BigSize, TLV and truncated-integer codecs are gone.
* Secret keys (SecretKey) must be exactly 32 bytes encoding a valid
scalar. Secret keys, shared secrets and payment secrets are
abstract, with redacted Show instances; shared and payment
secrets compare in constant time.
* process takes the path_key received with an onion, derives the
blinded private key, decrypts encrypted_recipient_data (using
path_key or current_path_key) and returns its contents and the
next path key.
* Hop payloads and encrypted_data_tlv streams reject unknown even
types and keep unknown odd ones, so re-encoding is exact.
payment_metadata and total_amount_msat are typed fields.
* Failures are a typed sum of every failure code in the spec, with
an escape hatch for unknown codes; invalid_realm is gone, and
required_channel_feature_missing, unknown_next_peer and
invalid_onion_blinding are new.
* unwrap_error reports the hop whose HMAC matches even when its
failure message is malformed. wrap_error is total, and
construct_error fails only on an unencodable failure message.
* Fixes onion construction for routes of three or more hops, the
framing and padding of failure messages, and decoding of payload
lengths past the end of hop_payloads, overlong TLV lengths and
unknown even TLV types.
* The onion HMAC check is constant time.
* Tests now cover the onion, error, route blinding and blinded
payment test vectors of BOLT #4, through the public API.
* Adds NFData instances, and criterion and weigh benchmarks.
- 0.0.1 (2026-04-18)
* Initial release.