What changed, and why it matters
This commit updates the RapidJSON submodule used by Monero and adds a Windows-specific workaround in the Trezor hardware wallet transport code. The workaround undefines the Windows macro 'GetObject' before including RapidJSON headers, because that macro conflicts with a RapidJSON method name. This is a compatibility fix for a known upstream issue, not a direct security patch. It likely prevents build or runtime problems on Windows when communicating with Trezor devices, but the commit itself does not describe any vulnerability or exploit.
Review the RapidJSON submodule update to identify the exact version change and check whether it includes any security fixes. Verify that the GetObject workaround does not break other Windows builds or introduce unexpected behavior. Consider whether the submodule update itself addresses any known RapidJSON vulnerabilities and assess accordingly.
Security signals we found
Submodule update to RapidJSON, a JSON parsing library with a history of security-relevant bugs
Windows-specific macro undefinition to prevent API name collision
Change is in Trezor hardware wallet transport layer, which handles sensitive device communication
No explicit security claim, CVE, or vulnerability description in commit message or diff
Evidence from the diff
The diff updates the external/rapidjson submodule and modifies src/device_trezor/trezor/transport.cpp to add ‘#ifdef _WIN32 #undef GetObject #endif’ before ‘#include
Changed components
external/rapidjson submodulesrc/device_trezor/trezor/transport.cppTrezor device communication on Windows buildsInspect captured patch +7 / −1
diff --git a/src/device_trezor/trezor/transport.cpp b/src/device_trezor/trezor/transport.cpp
index ec39dc3..66a1c76 100644
--- a/src/device_trezor/trezor/transport.cpp
+++ b/src/device_trezor/trezor/transport.cpp
@@ -42,6 +42,12 @@
#include "transport.hpp"
#include "messages/messages-common.pb.h"
+// https://github.com/Tencent/rapidjson/issues/1448
+#ifdef _WIN32
+#undef GetObject
+#endif
+#include <rapidjson/document.h>
+
#undef MONERO_DEFAULT_LOG_CATEGORY
#define MONERO_DEFAULT_LOG_CATEGORY "device.trezor.transport"
Why this scored 35/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.