AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 26 Cryptographic libraries

rpc: speedup block&tx RPC calls

Public commit record

What the developer wrote

Authored by jeffro256

68/100 · Adequate
rpc: speedup block&tx RPC calls

In RPC calls `get_blocks.bin` and `get_transactions`:
1. Skip deserializing then re-serializing tx blobs
2. Provide full unpruned transaction from mempool in `get_transactions` when `!req.prune`
3. Change `on_get_transactions()` response sort time from O(N^2) to O(N)
4. Generally improve memory usage and lookups in `on_get_transactions()`

Reviewed-by: selsta <selsta@sent.at>
Reviewed-by: j-berman <justinberman@protonmail.com>
Reviewed-by: jpk68 <jpk68@tutanota.com>
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit is a performance optimization for Monero's RPC endpoints that fetch blocks and transactions. It replaces slow full transaction parsing with a lightweight custom parser, avoids unnecessary re-serialization, and improves how mempool transactions are returned. The changes touch security-relevant code paths (parsing untrusted transaction blobs and deciding what data to expose), but the commit itself is framed as a speedup, not a security fix. There is no direct evidence in the commit message or diff of a vulnerability being fixed, though the new parser could in principle introduce parsing bugs.

Recommended action

Treat as a routine performance refactor with security-adjacent changes. Review the new `get_transaction_unprunable_summary()` parser for correctness, especially boundary checks, varint overflow, and future FCMP++ compatibility. Verify that the restricted RPC change `!restricted` is intentional and does not expose sensitive mempool data to restricted callers. Run differential fuzzing against the old full-deserialization path to detect parsing discrepancies.

Security signals we found

01

New custom binary parser `get_transaction_unprunable_summary()` parses untrusted tx blobs with manual varint/length checks

02

Parser rejects unknown input/output variant tags and oversized extra fields, which is defensive

03

Parser has an explicit TODO noting it needs updating for future FCMP++ transaction types

04

Restricted RPC logic changed: `!request_has_rpc_origin || !restricted` simplified to `!restricted`

05

Mempool transactions now returned as raw blobs and split into pruned/prunable parts by the server

06

No mention of CVE, security bug, bug bounty, or vulnerability in commit message

Risk score

Why this scored 26/100

Our methodology →
Potential impact 5/30
Exploitability 4/25
Stealth signal 3/15
Affected reach 6/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.