Wallet API: setStatusCritical for recoverFromDevice
What changed, and why it matters
This commit changes one line in Monero's wallet API. When recovering a wallet from a hardware device fails, the code now marks the error as 'critical' rather than just a regular error. This is a status/severity classification change, not a fix for a code vulnerability. It may help downstream callers notice recovery failures more clearly, but it does not by itself prevent or enable any attack.
No security action required. Treat as a normal API behavior/severity classification improvement. Review whether callers of recoverFromDevice handle critical status appropriately, but this is outside the scope of this single-line change.
Security signals we found
Status-severity change only
No change to error string or control flow
No cryptographic or memory-safety modifications
No input validation or authorization changes
Evidence from the diff
In WalletImpl::recoverFromDevice(), the exception handler now calls setStatusCritical() instead of setStatusError(). The error string remains identical. This is a severity-level change in the wallet status API; it does not alter control flow, exception handling, cryptographic operations, or memory safety. There is no direct security bug being patched.
Changed components
src/wallet/api/wallet.cppWalletImpl::recoverFromDeviceInspect captured patch +1 / −1
diff --git a/src/wallet/api/wallet.cpp b/src/wallet/api/wallet.cpp
index 07e09dd..460650f 100644
--- a/src/wallet/api/wallet.cpp
+++ b/src/wallet/api/wallet.cpp
@@ -698,7 +698,7 @@ bool WalletImpl::recoverFromDevice(const std::string &path, const std::string &p
LOG_PRINT_L1("Generated new wallet from device: " + device_name);
}
catch (const std::exception& e) {
- setStatusError(string(tr("failed to generate new wallet: ")) + e.what());
+ setStatusCritical(string(tr("failed to generate new wallet: ")) + e.what());
return false;
}
m_password = password;
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.