wallet: add source info to describe_transfer RPC
What changed, and why it matters
This commit adds more detailed information about where transaction inputs come from to a wallet RPC command called describe_transfer. It is a feature enhancement that exposes source details (amount, global index, ring signature type, public key) to RPC callers. There is no indication in the commit that this fixes a security vulnerability or introduces a dangerous capability.
No security action required. Treat as normal feature/API update. Reviewers may consider whether the newly exposed source details (global index, pubkey) are acceptable to return to all authenticated RPC callers, but this is a privacy/information-disclosure design question rather than a vulnerability.
Security signals we found
No security-relevant signals present in commit message or diff
Additive RPC response field only; no privilege boundary change
No input validation, memory safety, or cryptographic changes observed
Evidence from the diff
The patch extends the COMMAND_RPC_DESCRIBE_TRANSFER response structure with a new ‘source’ sub-object containing amount, global_index, rct flag, and pubkey for each tx source entry. It populates these fields in wallet_rpc_server.cpp and bumps the wallet RPC minor version from 29 to 30. This is an additive API change.
Changed components
src/wallet/wallet_rpc_server.cppsrc/wallet/wallet_rpc_server_commands_defs.hwallet RPC API (describe_transfer)Inspect captured patch +27 / −4
diff --git a/src/wallet/wallet_rpc_server.cpp b/src/wallet/wallet_rpc_server.cpp
index 7761348..a070636 100644
--- a/src/wallet/wallet_rpc_server.cpp
+++ b/src/wallet/wallet_rpc_server.cpp
@@ -1529,7 +1529,7 @@ namespace tools
for (size_t n = 0; n < tx_constructions.size(); ++n)
{
const tools::wallet2::tx_construction_data &cd = tx_constructions[n];
- res.desc.push_back({0, 0, std::numeric_limits<uint32_t>::max(), 0, {}, "", 0, "", 0, 0, ""});
+ res.desc.push_back({0, 0, std::numeric_limits<uint32_t>::max(), 0, {}, {}, "", 0, "", 0, 0, ""});
wallet_rpc::COMMAND_RPC_DESCRIBE_TRANSFER::transfer_description &desc = res.desc.back();
// Clear the recipients collection ready for this loop iteration
tx_dests.clear();
@@ -1560,8 +1560,14 @@ namespace tools
for (size_t s = 0; s < cd.sources.size(); ++s)
{
- desc.amount_in += cd.sources[s].amount;
- size_t ring_size = cd.sources[s].outputs.size();
+ const cryptonote::tx_source_entry &src_in = cd.sources[s];
+ wallet_rpc::COMMAND_RPC_DESCRIBE_TRANSFER::source &src_out = desc.sources.emplace_back();
+ src_out.amount = src_in.amount;
+ src_out.global_index = src_in.outputs.at(src_in.real_output_in_tx_index).first;
+ src_out.rct = src_in.rct;
+ src_out.pubkey = epee::string_tools::pod_to_hex(src_in.outputs.at(src_in.real_output_in_tx_index).second);
+ desc.amount_in += src_in.amount;
+ size_t ring_size = src_in.outputs.size();
if (ring_size < desc.ring_size)
desc.ring_size = ring_size;
}
diff --git a/src/wallet/wallet_rpc_server_commands_defs.h b/src/wallet/wallet_rpc_server_commands_defs.h
index 317add9..e6332d2 100644
--- a/src/wallet/wallet_rpc_server_commands_defs.h
+++ b/src/wallet/wallet_rpc_server_commands_defs.h
@@ -47,7 +47,7 @@
// advance which version they will stop working with
// Don't go over 32767 for any of these
#define WALLET_RPC_VERSION_MAJOR 1
-#define WALLET_RPC_VERSION_MINOR 29
+#define WALLET_RPC_VERSION_MINOR 30
#define MAKE_WALLET_RPC_VERSION(major,minor) (((major)<<16)|(minor))
#define WALLET_RPC_VERSION MAKE_WALLET_RPC_VERSION(WALLET_RPC_VERSION_MAJOR, WALLET_RPC_VERSION_MINOR)
namespace tools
@@ -698,6 +698,21 @@ namespace wallet_rpc
struct COMMAND_RPC_DESCRIBE_TRANSFER
{
+ struct source
+ {
+ uint64_t amount;
+ uint64_t global_index;
+ bool rct;
+ std::string pubkey;
+
+ BEGIN_KV_SERIALIZE_MAP()
+ KV_SERIALIZE(amount)
+ KV_SERIALIZE(global_index)
+ KV_SERIALIZE(rct)
+ KV_SERIALIZE(pubkey)
+ END_KV_SERIALIZE_MAP()
+ };
+
struct recipient
{
std::string address;
@@ -715,6 +730,7 @@ namespace wallet_rpc
uint64_t amount_out;
uint32_t ring_size;
uint64_t unlock_time;
+ std::list<source> sources;
std::list<recipient> recipients;
std::string payment_id;
uint64_t change_amount;
@@ -728,6 +744,7 @@ namespace wallet_rpc
KV_SERIALIZE(amount_out)
KV_SERIALIZE(ring_size)
KV_SERIALIZE(unlock_time)
+ KV_SERIALIZE(sources)
KV_SERIALIZE(recipients)
KV_SERIALIZE(payment_id)
KV_SERIALIZE(change_amount)
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.