simplewallet: skip redundant get_tx_key unless needed
What changed, and why it matters
This is a small cleanup change in Monero's command-line wallet. It moves a call that retrieves a transaction's secret key so it only runs when the user actually asked to export keys. Previously, the key was retrieved for every exported transfer even if keys were not being exported. There is no direct security vulnerability here, but retrieving secret key material unnecessarily is a minor defensive-coding concern.
No urgent action required. The change is a safe hardening improvement. Users running older code are not at direct risk, but applying the patch reduces unnecessary secret-key access.
Security signals we found
Unnecessary retrieval of secret key material (tx_key) outside the feature branch that uses it
Defensive reduction of secret-key exposure scope
No cryptographic weakness, memory corruption, or authentication bypass present in diff
Evidence from the diff
In simple_wallet::export_transfers(), the code previously declared tx_key and additional_tx_keys and called m_wallet->get_tx_key() unconditionally before checking export_keys. The patch moves that work inside the if (export_keys) block, so secret key material is only fetched when the caller requested key export. This reduces unnecessary handling of sensitive data and avoids a redundant wallet lookup.
Changed components
src/simplewallet/simplewallet.cppsimple_wallet::export_transfers()Inspect captured patch +5 / −5
diff --git a/src/simplewallet/simplewallet.cpp b/src/simplewallet/simplewallet.cpp
index bb1f6e8..69d810c 100644
--- a/src/simplewallet/simplewallet.cpp
+++ b/src/simplewallet/simplewallet.cpp
@@ -8627,13 +8627,13 @@ bool simple_wallet::export_transfers(const std::vector<std::string>& args_)
running_balance -= transfer.amount + transfer.fee;
}
- crypto::secret_key tx_key;
- std::vector<crypto::secret_key> additional_tx_keys;
- bool found_tx_key = m_wallet->get_tx_key(transfer.hash, tx_key, additional_tx_keys);
std::string key_string;
- if (export_keys && found_tx_key)
+ if (export_keys)
{
- key_string = get_tx_key_stream(tx_key, additional_tx_keys);
+ crypto::secret_key tx_key;
+ std::vector<crypto::secret_key> additional_tx_keys;
+ if (m_wallet->get_tx_key(transfer.hash, tx_key, additional_tx_keys))
+ key_string = get_tx_key_stream(tx_key, additional_tx_keys);
}
file << formatter
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.