wallet2: sanitize untrusted daemon status in sweep unmixable
What changed, and why it matters
This commit changes how a Monero wallet handles error status codes returned by a remote daemon during a cleanup operation called 'sweep unmixable.' Previously, the wallet trusted the daemon's raw status response. Now it passes that status through a helper that treats certain errors differently when the daemon is not trusted. This is a hardening fix: a malicious or compromised remote node could potentially return a misleading status code that the wallet would treat as a fatal error, possibly disrupting the operation or influencing wallet behavior. The patch narrows what the wallet believes from an untrusted daemon.
Treat as a security hardening fix. Review whether other RPC calls in wallet2.cpp still pass raw resp_t.status to THROW_ON_RPC_RESPONSE_ERROR when interacting with untrusted daemons, and apply the same get_rpc_status(m_trusted_daemon, ...) pattern consistently. Users should upgrade wallets and avoid marking unknown remote daemons as trusted.
Security signals we found
Untrusted daemon input used in error-handling decision
RPC response status sanitized before being passed to error macro
Pattern consistent with other wallet2 hardening against malicious remote nodes
No explicit vulnerability description or CVE in commit materials
Evidence from the diff
In wallet2::select_available_outputs_from_histogram, the RPC error handling for get_output_histogram was changed from passing resp_t.status directly to THROW_ON_RPC_RESPONSE_ERROR to passing get_rpc_status(m_trusted_daemon, resp_t.status). The get_rpc_status helper is designed to sanitize daemon-reported status based on whether the daemon is marked trusted. The change prevents an untrusted daemon’s raw status string from being used to decide whether the wallet throws an RPC error. This is a one-line defensive patch in the sweep unmixable flow.
Changed components
src/wallet/wallet2.cppwallet2::select_available_outputs_from_histogramsweep unmixable transaction flowdaemon RPC get_output_histogram handlingInspect captured patch +1 / −1
### src/wallet/wallet2.cpp
@@ -11797,7 +11797,7 @@ std::vector<size_t> wallet2::select_available_outputs_from_histogram(uint64_t co
{
const boost::lock_guard<boost::recursive_mutex> lock{m_daemon_rpc_mutex};
bool r = net_utils::invoke_http_json_rpc("/json_rpc", "get_output_histogram", req_t, resp_t, *m_http_client, rpc_timeout);
- THROW_ON_RPC_RESPONSE_ERROR(r, {}, resp_t, "get_output_histogram", error::get_histogram_error, resp_t.status);
+ THROW_ON_RPC_RESPONSE_ERROR(r, {}, resp_t, "get_output_histogram", error::get_histogram_error, get_rpc_status(m_trusted_daemon, resp_t.status));
}
std::set<uint64_t> mixable;Why this scored 46/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.