What changed, and why it matters
This commit only silences compiler warnings about unused function return values. It does not fix a security vulnerability. One change makes a test program check whether protobuf serialization succeeded, and the other explicitly discards return values from default_instance() calls that are only meant to trigger package initialization.
No security action required. Treat as routine code-quality/maintenance commit.
Security signals we found
No security-relevant behavioral change
Compiler warning cleanup only
No input parsing or memory handling changes
No privilege boundary crossed
Evidence from the diff
The patch addresses two instances of -Wunused-result warnings. In cmake/test-protobuf.cpp, the return value of SerializeToOstream is now checked, causing the test program to return -1 on failure. In src/device_trezor/trezor/messages_map.cpp, (void) casts are added to default_instance() calls whose side effect is to ensure protobuf message descriptors are registered; the return values were never intended to be used. Neither change alters security-relevant behavior in production code.
Changed components
cmake/test-protobuf.cppsrc/device_trezor/trezor/messages_map.cppInspect captured patch +6 / −4
diff --git a/cmake/test-protobuf.cpp b/cmake/test-protobuf.cpp
index eab6dd9..8d77964 100644
--- a/cmake/test-protobuf.cpp
+++ b/cmake/test-protobuf.cpp
@@ -38,6 +38,8 @@ int main(int argc, char *argv[]) {
Success sc;
sc.set_message("test");
- sc.SerializeToOstream(&std::cerr);
+ if (!sc.SerializeToOstream(&std::cerr)) {
+ return -1;
+ }
return 0;
}
diff --git a/src/device_trezor/trezor/messages_map.cpp b/src/device_trezor/trezor/messages_map.cpp
index 79fd876..2f275e7 100644
--- a/src/device_trezor/trezor/messages_map.cpp
+++ b/src/device_trezor/trezor/messages_map.cpp
@@ -71,9 +71,9 @@ namespace trezor
google::protobuf::Message * MessageMapper::get_message(const std::string & msg_name) {
// Each package instantiation so lookup works
- hw::trezor::messages::common::Success::default_instance();
- hw::trezor::messages::management::Cancel::default_instance();
- hw::trezor::messages::monero::MoneroGetAddress::default_instance();
+ (void)hw::trezor::messages::common::Success::default_instance();
+ (void)hw::trezor::messages::management::Cancel::default_instance();
+ (void)hw::trezor::messages::monero::MoneroGetAddress::default_instance();
#ifdef WITH_TREZOR_DEBUGGING
hw::trezor::messages::debug::DebugLinkDecision::default_instance();
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.