AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 17 Monero

build: remove direct X11 dependency

Public commit record

What the developer wrote

Authored by selsta

80/100 · Strong
build: remove direct X11 dependency

X11 was only used for Caps Lock detection on Linux. This small feature does
not justify linking against X11 directly, especially as the upcoming Qt6
migration should avoid unnecessary platform-specific dependencies.

Return false on platforms without native Caps Lock support instead. The
existing X11-based implementation would not work on Wayland anyway.

Also fix the Windows check to mask the Caps Lock toggle bit explicitly.
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit removes the Monero GUI wallet's direct dependency on the X11 graphics library on Linux. Previously, X11 was used only to detect whether Caps Lock is on when the user types their password. After the change, Linux systems without native Caps Lock support (including Wayland) will simply report that Caps Lock is off. The commit also fixes a minor Windows Caps Lock check so it correctly reads the on/off toggle bit. There is no obvious security vulnerability here, but users on Linux without native support may get less warning when Caps Lock is active.

Recommended action

No urgent action required. Reviewers may want to confirm that Qt's own Caps Lock handling still provides adequate feedback on Linux/Wayland, and verify the Windows bit-mask change behaves correctly on high-contrast/toggle states. Consider whether the loss of the Caps Lock warning on Linux is an acceptable UX trade-off.

Security signals we found

01

Removal of direct X11 dependency reduces attack surface from linking a large legacy client library

02

Caps Lock detection now returns false on Linux without native support, potentially weakening a UI warning that helps users avoid password-entry mistakes

03

Windows Caps Lock bit-mask fix corrects an overly strict equality check (GetKeyState returns a signed short with the toggle bit set, not necessarily exactly 1)

Risk score

Why this scored 17/100

Our methodology →
Potential impact 2/30
Exploitability 1/25
Stealth signal 1/15
Affected reach 3/15
Confidence 7/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.