wallet_rpc_server: add missing trusted daemon check
What changed, and why it matters
This commit adds a safety check to a Monero wallet command called rescan_spent. Previously, the command could be run even when the wallet was connected to a daemon it did not trust. The fix now refuses to run the command unless the daemon is marked as trusted. This matters because an untrusted daemon could potentially lie about which coins have been spent, which may confuse the wallet's balance or, in the worst case, be used to manipulate transaction creation.
Review other wallet RPC handlers that query daemon state for spent outputs, balances, or key images to ensure they also require a trusted daemon where appropriate. Verify that the trusted-daemon flag is set accurately and cannot be bypassed by RPC clients. Consider adding regression tests for RPC behavior against untrusted daemons.
Security signals we found
Missing authorization/trust check added to sensitive RPC
Daemon trust boundary enforced for spent-output rescan
Potential for untrusted daemon to influence wallet state
Evidence from the diff
The patch inserts a guard at the start of wallet_rpc_server::on_rescan_spent that returns an error if m_wallet->is_trusted_daemon() is false. The rescan_spent operation refreshes the wallet’s knowledge of spent outputs by querying the daemon. Without the trusted-daemon requirement, a malicious or compromised remote daemon could return false spent-status data. The fix aligns this RPC with the trust model already used elsewhere in the wallet, but the patch is minimal and does not show the broader context of how the trust flag is set or whether other RPCs share the same gap.
Changed components
src/wallet/wallet_rpc_server.cppwallet_rpc_server::on_rescan_spentCOMMAND_RPC_RESCAN_SPENTInspect captured patch +6 / −0
diff --git a/src/wallet/wallet_rpc_server.cpp b/src/wallet/wallet_rpc_server.cpp
index 9edfb1b..f19e645 100644
--- a/src/wallet/wallet_rpc_server.cpp
+++ b/src/wallet/wallet_rpc_server.cpp
@@ -3464,6 +3464,12 @@ namespace tools
bool wallet_rpc_server::on_rescan_spent(const wallet_rpc::COMMAND_RPC_RESCAN_SPENT::request& req, wallet_rpc::COMMAND_RPC_RESCAN_SPENT::response& res, epee::json_rpc::error& er, const connection_context *ctx)
{
CHECK_IF_RESTRICTED_BACKGROUND_SYNCING();
+ if (!m_wallet->is_trusted_daemon())
+ {
+ er.code = WALLET_RPC_ERROR_CODE_UNKNOWN_ERROR;
+ er.message = "This command requires a trusted daemon.";
+ return false;
+ }
try
{
m_wallet->rescan_spent();
Why this scored 60/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.