What changed, and why it matters
This commit tightens limits on a Monero RPC command called add_aux_pow that is used to add auxiliary proof-of-work data. When the RPC server runs in restricted mode, it now rejects requests with more than 10 auxiliary hashes and lowers the maximum nonce search from 65,535 to 16,384. The change appears aimed at preventing a restricted/public RPC endpoint from being abused to perform expensive CPU or memory work, which could be used to slow down or overload a node.
Treat this as a likely resource-consumption hardening fix. Node operators running restricted RPC should upgrade. Reviewers should verify whether unrestricted/local callers can still trigger the same heavy path, and consider whether additional limits (total payload size, per-hash cost, rate limiting) are needed. No CVE or advisory is supplied, so track this as defense-in-depth unless further disclosure emerges.
Security signals we found
Resource-limiting patch on a public/restricted RPC endpoint
Input-size cap added (aux_pow.size() > 10)
Computational-budget reduction (max_nonce 65535 -> 16384) under restricted mode
Use of CORE_RPC_ERROR_CODE_RESTRICTED suggests defense-in-depth for restricted RPC users
Evidence from the diff
In src/rpc/core_rpc_server.cpp, the handler for COMMAND_RPC_ADD_AUX_POW now checks m_restricted && ctx and, if restricted, rejects requests where req.aux_pow.size() > 10 with CORE_RPC_ERROR_CODE_RESTRICTED. It also reduces the nonce upper bound from 65535 to 16384 for restricted callers. The unauthenticated/restricted RPC path therefore limits both input size and computational work for this endpoint. The patch is partial: it does not add the same limits for unrestricted/local callers, and it does not document why 10 and 16384 were chosen.
Changed components
src/rpc/core_rpc_server.cppCOMMAND_RPC_ADD_AUX_POW RPC handlerRestricted RPC server modeInspect captured patch +10 / −1
diff --git a/src/rpc/core_rpc_server.cpp b/src/rpc/core_rpc_server.cpp
index bf4cdb4..ed8b536 100644
--- a/src/rpc/core_rpc_server.cpp
+++ b/src/rpc/core_rpc_server.cpp
@@ -2138,6 +2138,15 @@ namespace cryptonote
if (use_bootstrap_daemon_if_necessary<COMMAND_RPC_ADD_AUX_POW>(invoke_http_mode::JON_RPC, "add_aux_pow", req, res, r))
return r;
+ const bool restricted = m_restricted && ctx;
+
+ if (restricted && req.aux_pow.size() > 10)
+ {
+ error_resp.code = CORE_RPC_ERROR_CODE_RESTRICTED;
+ error_resp.message = "Too many aux pow hashes";
+ return false;
+ }
+
if (req.aux_pow.empty())
{
error_resp.code = CORE_RPC_ERROR_CODE_WRONG_PARAM;
@@ -2173,7 +2182,7 @@ namespace cryptonote
while ((1u << path_domain) < aux_pow.size())
++path_domain;
uint32_t nonce;
- const uint32_t max_nonce = 65535;
+ const uint32_t max_nonce = restricted ? 16384 : 65535;
bool collision = true;
std::vector<uint32_t> slots(aux_pow.size());
for (nonce = 0; nonce <= max_nonce; ++nonce)
Why this scored 49/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.