simplewallet: add missing guards/locks for multisig commands
What changed, and why it matters
This commit adds two safety checks to Monero's command-line wallet for multisignature (multisig) setup commands. One prevents converting a wallet to multisig while a background sync is running, and the other prevents certain idle/background tasks from running during the key-exchange step. These are hardening fixes that reduce the chance of wallet state corruption or unsafe key handling, but the commit itself does not describe a specific exploit or known attack.
Treat as a defensive hardening patch. Review whether the same guards are needed in other multisig-related commands (e.g., finalize_multisig, export_multisig_info, import_multisig_info) and in GUI wallet paths. No immediate emergency response is indicated by the available evidence.
Security signals we found
Missing concurrency guard added (LOCK_IDLE_SCOPE)
Missing background-sync guard added (CHECK_IF_BACKGROUND_SYNCING)
Multisig key-exchange code path touched
No CVE, advisory, or exploit description present in commit or references
Evidence from the diff
The patch modifies src/simplewallet/simplewallet.cpp. In make_multisig_main it adds CHECK_IF_BACKGROUND_SYNCING(“cannot be made multisig”) before proceeding with multisig creation. In exchange_multisig_keys_main it adds LOCK_IDLE_SCOPE() around the call to m_wallet->exchange_multisig_keys(…). Both changes are guards/locks intended to serialize multisig operations against background activity. The diff does not include any explanatory security analysis, CVE, or reproduction scenario.
Changed components
src/simplewallet/simplewallet.cppsimple_wallet::make_multisig_mainsimple_wallet::exchange_multisig_keys_mainInspect captured patch +3 / −0
diff --git a/src/simplewallet/simplewallet.cpp b/src/simplewallet/simplewallet.cpp
index 066c1d1..7655199 100644
--- a/src/simplewallet/simplewallet.cpp
+++ b/src/simplewallet/simplewallet.cpp
@@ -1161,6 +1161,7 @@ bool simple_wallet::make_multisig_main(const std::vector<std::string> &args, boo
fail_msg_writer() << tr("wallet is watch-only and cannot be made multisig");
return false;
}
+ CHECK_IF_BACKGROUND_SYNCING("cannot be made multisig");
if(m_wallet->get_num_transfer_details())
{
@@ -1270,6 +1271,8 @@ bool simple_wallet::exchange_multisig_keys_main(const std::vector<std::string> &
return false;
}
+ LOCK_IDLE_SCOPE();
+
try
{
std::string multisig_extra_info = m_wallet->exchange_multisig_keys(orig_pwd_container->password(), args, force_update_use_with_caution);
Why this scored 42/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.