src: fix issues found through static analysis
What changed, and why it matters
This commit fixes several issues flagged by static analysis tools. Most changes add missing virtual destructors to C++ interface/base classes and remove unused function declarations. Missing virtual destructors can cause subtle memory bugs when objects are deleted through a base-class pointer, but the commit does not show any active crash or exploit path. It is a cleanup/hardening patch rather than a fix for a known active vulnerability.
Treat as routine hardening/cleanup. Review whether any code path currently deletes derived objects through these base pointers; if so, this patch prevents potential memory corruption or leaks. No urgent action is required absent evidence of an active exploit.
Security signals we found
Missing virtual destructors added to polymorphic base classes
Unused function declarations removed (dead-code cleanup)
Commit title and message attribute all changes to static-analysis findings
No active vulnerability, crash, or exploit path shown in the diff
Evidence from the diff
The diff makes two kinds of changes: (1) adds virtual ~T() = default; to five interface/base classes (i_network_throttle, i_cryptonote_protocol, device_progress, device_io, i_p2p_endpoint) and changes one non-virtual destructor to virtual; (2) removes two unused function declarations (jh_hash in src/crypto/jh.c and generate_output_ephemeral_keys in cryptonote_tx_utils.h). The virtual-destructor additions prevent potential undefined behavior when derived objects are destroyed through base pointers, which static analyzers commonly flag. The removed declarations are dead code. No concrete bug, crash, or exploit is demonstrated in the diff or references.
Changed components
contrib/epee/include/net/network_throttle.hppsrc/crypto/jh.csrc/cryptonote_core/cryptonote_tx_utils.hsrc/cryptonote_protocol/cryptonote_protocol_handler_common.hsrc/device/device.hppsrc/device/device_io.hppsrc/p2p/net_node_common.hInspect captured patch +5 / −10
diff --git a/contrib/epee/include/net/network_throttle.hpp b/contrib/epee/include/net/network_throttle.hpp
index 1acb0c3..d6d10cb 100644
--- a/contrib/epee/include/net/network_throttle.hpp
+++ b/contrib/epee/include/net/network_throttle.hpp
@@ -110,6 +110,7 @@ class network_throttle_manager {
*/
class i_network_throttle {
public:
+ virtual ~i_network_throttle() = default;
virtual void set_name(const std::string &name)=0;
virtual void set_target_speed( network_speed_kbps target )=0;
virtual network_speed_kbps get_target_speed()=0;
diff --git a/src/crypto/jh.c b/src/crypto/jh.c
index b156b3a..b4fa715 100644
--- a/src/crypto/jh.c
+++ b/src/crypto/jh.c
@@ -97,7 +97,6 @@ static void F8(hashState *state); /*The compression function F8 */
static HashReturn Init(hashState *state, int hashbitlen);
static HashReturn Update(hashState *state, const BitSequence *data, DataLength databitlen);
static HashReturn Final(hashState *state, BitSequence *hashval);
-HashReturn jh_hash(int hashbitlen, const BitSequence *data,DataLength databitlen, BitSequence *hashval);
/*swapping bit 2i with bit 2i+1 of 64-bit x*/
#define SWAP1(x) (x) = ((((x) & 0x5555555555555555ULL) << 1) | (((x) & 0xaaaaaaaaaaaaaaaaULL) >> 1));
diff --git a/src/cryptonote_core/cryptonote_tx_utils.h b/src/cryptonote_core/cryptonote_tx_utils.h
index 2f305d9..e8c0f66 100644
--- a/src/cryptonote_core/cryptonote_tx_utils.h
+++ b/src/cryptonote_core/cryptonote_tx_utils.h
@@ -130,14 +130,6 @@ namespace cryptonote
crypto::public_key &out_eph_public_key,
const bool use_view_tags, crypto::view_tag &view_tag) ;
- bool generate_output_ephemeral_keys(const size_t tx_version, const cryptonote::account_keys &sender_account_keys, const crypto::public_key &txkey_pub, const crypto::secret_key &tx_key,
- const cryptonote::tx_destination_entry &dst_entr, const boost::optional<cryptonote::account_public_address> &change_addr, const size_t output_index,
- const bool &need_additional_txkeys, const std::vector<crypto::secret_key> &additional_tx_keys,
- std::vector<crypto::public_key> &additional_tx_public_keys,
- std::vector<rct::key> &amount_keys,
- crypto::public_key &out_eph_public_key,
- const bool use_view_tags, crypto::view_tag &view_tag) ;
-
bool generate_genesis_block(
block& bl
, std::string const & genesis_tx
diff --git a/src/cryptonote_protocol/cryptonote_protocol_handler_common.h b/src/cryptonote_protocol/cryptonote_protocol_handler_common.h
index df9249e..df2355e 100644
--- a/src/cryptonote_protocol/cryptonote_protocol_handler_common.h
+++ b/src/cryptonote_protocol/cryptonote_protocol_handler_common.h
@@ -40,6 +40,7 @@ namespace cryptonote
/************************************************************************/
struct i_cryptonote_protocol
{
+ virtual ~i_cryptonote_protocol() = default;
virtual bool is_synchronized() const = 0;
virtual bool relay_block(NOTIFY_NEW_FLUFFY_BLOCK::request& arg, cryptonote_connection_context& exclude_context)=0;
virtual bool relay_transactions(NOTIFY_NEW_TRANSACTIONS::request& arg, const boost::uuids::uuid& source, epee::net_utils::zone zone, relay_method tx_relay)=0;
diff --git a/src/device/device.hpp b/src/device/device.hpp
index 81caec9..2365320 100644
--- a/src/device/device.hpp
+++ b/src/device/device.hpp
@@ -70,6 +70,7 @@ namespace hw {
class device_progress {
public:
+ virtual ~device_progress() = default;
virtual double progress() const { return 0; }
virtual bool indeterminate() const { return false; }
};
diff --git a/src/device/device_io.hpp b/src/device/device_io.hpp
index c24fa29..cb83cbe 100644
--- a/src/device/device_io.hpp
+++ b/src/device/device_io.hpp
@@ -41,7 +41,7 @@ namespace hw {
public:
device_io() {};
- ~device_io() {};
+ virtual ~device_io() = default;
virtual void init() = 0;
virtual void release() = 0;
diff --git a/src/p2p/net_node_common.h b/src/p2p/net_node_common.h
index 625259e..0c45cf0 100644
--- a/src/p2p/net_node_common.h
+++ b/src/p2p/net_node_common.h
@@ -52,6 +52,7 @@ namespace nodetool
template<class t_connection_context>
struct i_p2p_endpoint
{
+ virtual ~i_p2p_endpoint() = default;
virtual bool relay_notify_to_list(int command, epee::levin::message_writer message, std::vector<std::pair<epee::net_utils::zone, boost::uuids::uuid>> connections)=0;
virtual epee::net_utils::zone send_txs(std::vector<cryptonote::blobdata> txs, const epee::net_utils::zone origin, const boost::uuids::uuid& source, cryptonote::relay_method tx_relay)=0;
virtual bool invoke_notify_to_peer(int command, epee::levin::message_writer message, const epee::net_utils::connection_context_base& context)=0;
Why this scored 26/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.