What changed, and why it matters
This commit makes three small code changes: two places now silently ignore Lightning/Bitcoin network timeout errors in addition to DNS errors, and one Flutter UI check was simplified from 'context.mounted' to 'mounted'. The SVG asset change is unrelated binary data. The main concern is that hiding timeout errors could mask network or service problems, but there is no direct evidence this creates a security vulnerability.
Treat as a routine bug-fix commit unless further review shows that suppressing timeout errors affects transaction state, balance reporting, or user confirmations. Review whether ignored timeouts can lead to stale Lightning invoice/address data being presented to the user. The UI change should be checked for BuildContext use-after-dispose issues.
Security signals we found
Exception swallowing expanded: SdkError_SparkError messages containing 'TimedOut' are now ignored in two wallet code paths
UI lifecycle check narrowed from context.mounted to mounted in send page
No vendor security disclosure, advisory, or researcher attribution present in commit or supplied references
Evidence from the diff
In cw_bitcoin/lib/electrum_wallet_addresses.dart and cw_bitcoin/lib/lightning/lightning_wallet.dart, the exception handling for SdkError_SparkError is widened so that errors whose message contains ‘TimedOut’ are no longer rethrown; they are swallowed like DNS errors. In lib/new-ui/pages/send_page.dart, a widget lifecycle check is changed from ‘context.mounted’ to ‘mounted’. The assets/new-ui/link_arrow.svg.vec change is a binary vector asset update with no discernible security relevance from the diff.
Changed components
cw_bitcoin/lib/electrum_wallet_addresses.dartcw_bitcoin/lib/lightning/lightning_wallet.dartlib/new-ui/pages/send_page.dartInspect captured patch +3 / −3
diff --git a/assets/new-ui/link_arrow.svg.vec b/assets/new-ui/link_arrow.svg.vec
index 23119558..fc4d2e23 100644
Binary files a/assets/new-ui/link_arrow.svg.vec and b/assets/new-ui/link_arrow.svg.vec differ
diff --git a/cw_bitcoin/lib/electrum_wallet_addresses.dart b/cw_bitcoin/lib/electrum_wallet_addresses.dart
index 84ba5be6..9c1620a8 100644
--- a/cw_bitcoin/lib/electrum_wallet_addresses.dart
+++ b/cw_bitcoin/lib/electrum_wallet_addresses.dart
@@ -892,7 +892,7 @@ abstract class ElectrumWalletAddressesBase extends WalletAddresses with Store {
}
} on SdkError_NetworkError catch (_) {
} on SdkError_SparkError catch (e) {
- if (!e.field0.contains("dns")) rethrow;
+ if (!e.field0.contains("dns") && !e.field0.contains("TimedOut")) rethrow;
} finally {
lightningAddress ??= lightningWallet!.cachedAddress;
}
diff --git a/cw_bitcoin/lib/lightning/lightning_wallet.dart b/cw_bitcoin/lib/lightning/lightning_wallet.dart
index bfc5647f..a386d529 100644
--- a/cw_bitcoin/lib/lightning/lightning_wallet.dart
+++ b/cw_bitcoin/lib/lightning/lightning_wallet.dart
@@ -154,7 +154,7 @@ class LightningWallet {
} on SdkError_NetworkError catch (_) {
return null;
} on SdkError_SparkError catch (e) {
- if (!e.field0.contains("dns")) rethrow;
+ if (!e.field0.contains("dns") && !e.field0.contains("TimedOut")) rethrow;
return null;
}
}
diff --git a/lib/new-ui/pages/send_page.dart b/lib/new-ui/pages/send_page.dart
index b27bf829..24601085 100644
--- a/lib/new-ui/pages/send_page.dart
+++ b/lib/new-ui/pages/send_page.dart
@@ -639,7 +639,7 @@ class _NewSendPageState extends State<NewSendPage> {
output.setFiatAmount(amount);
}
} else {
- final isAll = context.mounted && amount != S.of(context).all;
+ final isAll = mounted && amount != S.of(context).all;
if (output.sendAll && isAll) {
output.sendAll = false;
}
Why this scored 22/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.