ignore pointless throw [skip ci]
What changed, and why it matters
A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a minor behavior change, not a clear security fix, and the commit message explicitly calls the throw 'pointless'.
Treat as routine code cleanup. If the closed-state behavior is security-sensitive, review whether callers properly handle the returned 'closed' string and whether any caller previously relied on the exception for safety. No urgent action required based on this diff alone.
Security signals we found
Removal of an exception path in wallet lifecycle state handling
Change from fail-closed (throw) to fail-open (return string) on closed wallet
No input validation, bounds checking, or cryptographic changes present
Evidence from the diff
In cw_decred/lib/api/libdcrwallet.dart, the Libwallet.syncStatus() method no longer throws StateError(‘Closed’) when _closed is true; it now returns the literal string ‘closed’. This changes an exceptional control-flow path into a normal return. The commit message ‘[skip ci]’ and ‘ignore pointless throw’ indicate the author views this as cleanup rather than a security-relevant change. No other defensive checks are added, and no references to vulnerabilities are supplied.
Changed components
cw_decred/lib/api/libdcrwallet.dartLibwallet.syncStatus()Decred wallet integrationInspect captured patch +3 / −1
### cw_decred/lib/api/libdcrwallet.dart
@@ -441,7 +441,9 @@ class Libwallet {
}
Future<String> syncStatus(String walletName) async {
- if (_closed) throw StateError('Closed');
+ if (_closed) {
+ return "closed";
+ }
final completer = Completer<Object?>.sync();
final id = _idCounter++;
_activeRequests[id] = completer;Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.