wallet: rescan_blockchain missing keep_key_images
What changed, and why it matters
This commit fixes a bug in Monero's wallet RPC server where the rescan_blockchain command was not passing through a new keep_key_images option. A hard rescan normally destroys key images (the proof that a coin has already been spent), so the patch also blocks the contradictory combination of a hard rescan while trying to preserve key images. The change is mostly a missing-parameter fix, but mishandling key images could in theory affect wallet balance accuracy or spendability.
Treat as a routine correctness fix. Review the underlying wallet2::rescan_blockchain implementation to confirm that keep_key_images behaves safely on soft rescans and that no other RPC wrappers omit the flag. No urgent security response is indicated from the diff alone.
Security signals we found
Missing parameter forwarding in RPC wrapper
New input validation guard for contradictory flags
Key-image handling change in wallet rescan logic
Evidence from the diff
The wallet RPC command COMMAND_RPC_RESCAN_BLOCKCHAIN gains a new optional boolean field keep_key_images, defaulting to false. The server handler now forwards that flag to wallet2::rescan_blockchain. It also adds a guard: if both req.hard and req.keep_key_images are true, the call returns WALLET_RPC_ERROR_CODE_UNKNOWN_ERROR with the message ‘Cannot preserve key images on hard rescan’. Previously the RPC wrapper silently ignored keep_key_images, so callers could not request a soft rescan that preserves key images.
Changed components
src/wallet/wallet_rpc_server.cppsrc/wallet/wallet_rpc_server_commands_defs.hwallet RPC rescan_blockchain commandInspect captured patch +9 / −1
diff --git a/src/wallet/wallet_rpc_server.cpp b/src/wallet/wallet_rpc_server.cpp
index d68db3b..c7b6d7d 100644
--- a/src/wallet/wallet_rpc_server.cpp
+++ b/src/wallet/wallet_rpc_server.cpp
@@ -2360,10 +2360,16 @@ namespace tools
bool wallet_rpc_server::on_rescan_blockchain(const wallet_rpc::COMMAND_RPC_RESCAN_BLOCKCHAIN::request& req, wallet_rpc::COMMAND_RPC_RESCAN_BLOCKCHAIN::response& res, epee::json_rpc::error& er, const connection_context *ctx)
{
CHECK_IF_RESTRICTED_BACKGROUND_SYNCING();
+ if (req.hard && req.keep_key_images)
+ {
+ er.code = WALLET_RPC_ERROR_CODE_UNKNOWN_ERROR;
+ er.message = "Cannot preserve key images on hard rescan";
+ return false;
+ }
try
{
- m_wallet->rescan_blockchain(req.hard);
+ m_wallet->rescan_blockchain(req.hard, true, req.keep_key_images);
}
catch (const std::exception& e)
{
diff --git a/src/wallet/wallet_rpc_server_commands_defs.h b/src/wallet/wallet_rpc_server_commands_defs.h
index bb087ca..09d4ae9 100644
--- a/src/wallet/wallet_rpc_server_commands_defs.h
+++ b/src/wallet/wallet_rpc_server_commands_defs.h
@@ -1220,9 +1220,11 @@ namespace wallet_rpc
struct request_t
{
bool hard;
+ bool keep_key_images;
BEGIN_KV_SERIALIZE_MAP()
KV_SERIALIZE_OPT(hard, false)
+ KV_SERIALIZE_OPT(keep_key_images, false)
END_KV_SERIALIZE_MAP()
};
typedef epee::misc_utils::struct_init<request_t> request;
Why this scored 35/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.