What changed, and why it matters
This patch fixes a spot in the Monero wallet where an untrusted remote server (daemon) could supply a misleading 'status' field. Previously, the wallet used that raw status directly in its error handling, which could potentially make a malicious daemon's response look trustworthy or cause the wallet to misbehave. The fix passes the status through a helper that treats the daemon as untrusted unless the user has explicitly marked it trusted.
Review other THROW_ON_RPC_RESPONSE_ERROR call sites in wallet2.cpp to ensure they also use get_rpc_status(m_trusted_daemon, resp_t.status) where daemon trust matters. Consider adding a code comment or audit to prevent regression at this call site.
Security signals we found
Untrusted input from remote daemon used in error-handling path
Missing trust check on daemon-reported RPC status
Single-call-site hardening patch
Evidence from the diff
In wallet2::select_available_outputs_from_histogram(), the wallet calls get_output_histogram on the daemon and then checks the RPC response with THROW_ON_RPC_RESPONSE_ERROR. The old code used resp_t.status as the status argument, which is the daemon-reported status. The new code uses get_rpc_status(m_trusted_daemon, resp_t.status), a helper that returns CORE_RPC_STATUS_OK only when the daemon is trusted or the daemon-reported status is already OK. This prevents an untrusted daemon from spoofing a non-OK status value into the wallet’s error path. The change is minimal (+1/-1) and only covers this single call site.
Changed components
src/wallet/wallet2.cppwallet2::select_available_outputs_from_histogram()get_output_histogram RPC handlingInspect captured patch +1 / −1
### src/wallet/wallet2.cpp
@@ -11854,7 +11854,7 @@ std::vector<size_t> wallet2::select_available_outputs_from_histogram(uint64_t co
{
const boost::lock_guard<boost::recursive_mutex> lock{m_daemon_rpc_mutex};
bool r = net_utils::invoke_http_json_rpc("/json_rpc", "get_output_histogram", req_t, resp_t, *m_http_client, rpc_timeout);
- THROW_ON_RPC_RESPONSE_ERROR(r, {}, resp_t, "get_output_histogram", error::get_histogram_error, resp_t.status);
+ THROW_ON_RPC_RESPONSE_ERROR(r, {}, resp_t, "get_output_histogram", error::get_histogram_error, get_rpc_status(m_trusted_daemon, resp_t.status));
}
std::set<uint64_t> mixable;Why this scored 60/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.