wallet_rpc_server: add missing background check
What changed, and why it matters
This commit adds a safety check to the Monero wallet's remote-control interface (RPC server). The check prevents a specific operation—creating a cryptographic 'spend proof'—from running while the wallet is performing a background synchronization. Without this guard, the operation could potentially use incomplete or inconsistent wallet state, which might lead to incorrect proof results or unexpected behavior. The issue was reported by an independent contributor, ro1m.
Apply the patch. Review other RPC handlers for similar missing background-sync guards, and consider adding automated tests that exercise RPC calls during background synchronization to catch regressions.
Security signals we found
Missing state-consistency guard added to RPC handler
Operation that reads wallet transaction state now blocked during background sync
Pattern matches other handlers that already include CHECK_IF_BACKGROUND_SYNCING()
Reported by external contributor (ro1m)
Evidence from the diff
In src/wallet/wallet_rpc_server.cpp, the on_get_spend_proof RPC handler now calls CHECK_IF_BACKGROUND_SYNCING() immediately after the open-wallet check. This macro likely returns an error to the caller if the wallet is currently doing a background sync. The change is one line and aligns this handler with other RPC handlers that already include the same guard. The diff itself does not show what vulnerability existed, only that a previously missing state guard was added.
Changed components
src/wallet/wallet_rpc_server.cppwallet_rpc_server::on_get_spend_proof RPC handlerInspect captured patch +1 / −0
diff --git a/src/wallet/wallet_rpc_server.cpp b/src/wallet/wallet_rpc_server.cpp
index f19e645..8bf2b3f 100644
--- a/src/wallet/wallet_rpc_server.cpp
+++ b/src/wallet/wallet_rpc_server.cpp
@@ -2786,6 +2786,7 @@ namespace tools
bool wallet_rpc_server::on_get_spend_proof(const wallet_rpc::COMMAND_RPC_GET_SPEND_PROOF::request& req, wallet_rpc::COMMAND_RPC_GET_SPEND_PROOF::response& res, epee::json_rpc::error& er, const connection_context *ctx)
{
if (!m_wallet) return not_open(er);
+ CHECK_IF_BACKGROUND_SYNCING();
crypto::hash txid;
if (!epee::string_tools::hex_to_pod(req.txid, txid))
Why this scored 49/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.