wallet2: remove unused pool tx removed callback
What changed, and why it matters
This commit removes a leftover wallet callback function that did nothing useful. The callback was called after a transaction record had already been deleted, so the transaction ID it received was technically invalid (a 'dangling reference'). Because the callback had no real implementation and was not exposed through the public wallet API, this appears to be a cleanup of dead code rather than a fix for an actively exploitable bug. The main risk is avoiding undefined behavior if someone later tried to use that invalid reference.
Treat as routine code hygiene. No immediate security response is required, but verify that no external wallet implementations or plugins override `on_pool_tx_removed`, since the interface change is API-breaking for any such subclass. Consider running static analysis to confirm no similar dangling-reference patterns remain in callback invocations after container erasure.
Security signals we found
use-after-free-like pattern: reference to erased map element passed to callback
dead-code removal: empty default callback with no API wiring
defensive cleanup in wallet transaction handling
Evidence from the diff
The patch deletes on_pool_tx_removed from the i_wallet2_callback interface and its only invocation in wallet2::remove_obsolete_pool_txs. In the original code, m_unconfirmed_payments.erase(pit) invalidated the crypto::hash referenced by txid (which was bound to data inside the erased map entry), then m_callback->on_pool_tx_removed(txid) passed that dangling reference to a no-op default virtual method. The callback is not overridden or wired through the wallet API, so the dangling reference was never consumed in practice. The change is a defensive removal of unused, potentially unsafe code.
Changed components
src/wallet/wallet2.cppsrc/wallet/wallet2.hwallet2::remove_obsolete_pool_txsi_wallet2_callback::on_pool_tx_removedInspect captured patch +0 / −4
diff --git a/src/wallet/wallet2.cpp b/src/wallet/wallet2.cpp
index 8496cf6..d1a08e6 100644
--- a/src/wallet/wallet2.cpp
+++ b/src/wallet/wallet2.cpp
@@ -3596,8 +3596,6 @@ void wallet2::remove_obsolete_pool_txs(const std::vector<crypto::hash> &tx_hashe
{
MDEBUG("Removing " << txid << " from unconfirmed payments");
m_unconfirmed_payments.erase(pit);
- if (0 != m_callback)
- m_callback->on_pool_tx_removed(txid);
}
}
}
diff --git a/src/wallet/wallet2.h b/src/wallet/wallet2.h
index 90149b1..57900da 100644
--- a/src/wallet/wallet2.h
+++ b/src/wallet/wallet2.h
@@ -136,8 +136,6 @@ private:
virtual boost::optional<epee::wipeable_string> on_device_pin_request() { return boost::none; }
virtual boost::optional<epee::wipeable_string> on_device_passphrase_request(bool & on_device) { on_device = true; return boost::none; }
virtual void on_device_progress(const hw::device_progress& event) {};
- // Common callbacks
- virtual void on_pool_tx_removed(const crypto::hash &txid) {}
virtual ~i_wallet2_callback() {}
};
Why this scored 16/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.