What changed, and why it matters
This Monero wallet commit changes how proxy settings are handled. Previously, if you started the wallet with a global --proxy option, you could not later use the set_daemon command to pick a different proxy for a specific daemon. The commit removes that restriction, allowing set_daemon to override the global proxy. This is a behavior change that could matter for privacy and security, but the commit itself does not show an obvious vulnerability—just a relaxation of a guard rule.
Review whether allowing set_daemon to override --proxy is intentional and safe. If so, document the new precedence clearly. If not, restore a guard that prevents silently replacing the global proxy, or require explicit user confirmation. Audit RPC access controls around set_daemon because it can now change the wallet's active proxy.
Security signals we found
Relaxation of proxy-conflict guard
Daemon-specific proxy can override global --proxy
Potential for unexpected proxy change via RPC set_daemon
Privacy-relevant networking change in wallet
Evidence from the diff
The patch removes the prohibition against combining a global –proxy with a daemon-specific proxy in wallet2::set_daemon and the wallet RPC server’s set_daemon handler. It deletes has_proxy_option(), drops the CHECK_AND_ASSERT_MES2 guard, and makes set_daemon always call set_proxy(proxy) and store the supplied proxy in m_proxy. init() now passes proxy_address directly to set_daemon instead of setting m_proxy first. The effect is that a daemon-specific proxy can now override the global proxy rather than being rejected.
Changed components
src/wallet/wallet2.cppsrc/wallet/wallet2.hsrc/wallet/wallet_rpc_server.cppInspect captured patch +3 / −24
diff --git a/src/wallet/wallet2.cpp b/src/wallet/wallet2.cpp
index 44e9727..760e2fa 100644
--- a/src/wallet/wallet2.cpp
+++ b/src/wallet/wallet2.cpp
@@ -1299,11 +1299,6 @@ bool wallet2::has_password_option(const boost::program_options::variables_map& v
return command_line::has_arg(vm, options().password);
}
-bool wallet2::has_proxy_option() const
-{
- return !m_proxy.empty();
-}
-
std::string wallet2::device_name_option(const boost::program_options::variables_map& vm)
{
return command_line::get_arg(vm, options().hw_device);
@@ -1398,9 +1393,8 @@ bool wallet2::set_daemon(std::string daemon_address, boost::optional<epee::net_u
if(m_http_client->is_connected())
m_http_client->disconnect();
- CHECK_AND_ASSERT_MES2(m_proxy.empty() || proxy.empty() , "It is not possible to set global proxy (--proxy) and daemon specific proxy together.");
- if(m_proxy.empty())
- CHECK_AND_ASSERT_MES(set_proxy(proxy), false, "failed to set proxy address");
+ CHECK_AND_ASSERT_MES(set_proxy(proxy), false, "failed to set proxy address");
+ m_proxy = proxy;
const bool changed = m_daemon_address != daemon_address;
m_daemon_address = std::move(daemon_address);
m_daemon_login = std::move(daemon_login);
@@ -1430,12 +1424,10 @@ bool wallet2::set_proxy(const std::string &address)
//----------------------------------------------------------------------------------------------------
bool wallet2::init(std::string daemon_address, boost::optional<epee::net_utils::http::login> daemon_login, const std::string &proxy_address, uint64_t upper_transaction_weight_limit, bool trusted_daemon, epee::net_utils::ssl_options_t ssl_options)
{
- m_proxy = proxy_address;
- CHECK_AND_ASSERT_MES(set_proxy(m_proxy), false, "failed to set proxy address");
m_checkpoints.init_default_checkpoints(m_nettype);
m_is_initialized = true;
m_upper_transaction_weight_limit = upper_transaction_weight_limit;
- return set_daemon(daemon_address, daemon_login, trusted_daemon, std::move(ssl_options));
+ return set_daemon(daemon_address, daemon_login, trusted_daemon, std::move(ssl_options), proxy_address);
}
//----------------------------------------------------------------------------------------------------
bool wallet2::is_deterministic() const
diff --git a/src/wallet/wallet2.h b/src/wallet/wallet2.h
index 506561a..c15e5df 100644
--- a/src/wallet/wallet2.h
+++ b/src/wallet/wallet2.h
@@ -757,12 +757,6 @@ private:
std::string path() const;
- /*!
- * \brief has_proxy_option Check the global proxy (--proxy) has been defined or not.
- * \return returns bool representing the global proxy (--proxy).
- */
- bool has_proxy_option() const;
-
/*!
* \brief verifies given password is correct for default wallet keys file
*/
diff --git a/src/wallet/wallet_rpc_server.cpp b/src/wallet/wallet_rpc_server.cpp
index 71e47d1..8b51019 100644
--- a/src/wallet/wallet_rpc_server.cpp
+++ b/src/wallet/wallet_rpc_server.cpp
@@ -4797,13 +4797,6 @@ namespace tools
}
if (!m_wallet) return not_open(er);
- if (m_wallet->has_proxy_option() && !req.proxy.empty())
- {
- er.code = WALLET_RPC_ERROR_CODE_PROXY_ALREADY_DEFINED;
- er.message = "It is not possible to set daemon specific proxy when --proxy is defined.";
- return false;
- }
-
std::vector<std::vector<uint8_t>> ssl_allowed_fingerprints;
ssl_allowed_fingerprints.reserve(req.ssl_allowed_fingerprints.size());
for (const std::string &fp: req.ssl_allowed_fingerprints)
Why this scored 35/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.