What changed, and why it matters
This commit removes the Monero GUI wallet's direct dependency on the X11 graphics library on Linux. Previously, X11 was used only to detect whether Caps Lock is on when the user types their password. After the change, Linux systems without native Caps Lock support (including Wayland) will simply report that Caps Lock is off. The commit also fixes a minor Windows Caps Lock check so it correctly reads the on/off toggle bit. There is no obvious security vulnerability here, but users on Linux without native support may get less warning when Caps Lock is active.
No urgent action required. Reviewers may want to confirm that Qt's own Caps Lock handling still provides adequate feedback on Linux/Wayland, and verify the Windows bit-mask change behaves correctly on high-contrast/toggle states. Consider whether the loss of the Caps Lock warning on Linux is an acceptable UX trade-off.
Security signals we found
Removal of direct X11 dependency reduces attack surface from linking a large legacy client library
Caps Lock detection now returns false on Linux without native support, potentially weakening a UI warning that helps users avoid password-entry mistakes
Windows Caps Lock bit-mask fix corrects an overly strict equality check (GetKeyState returns a signed short with the toggle bit set, not necessarily exactly 1)
Evidence from the diff
The patch deletes CMake X11 discovery and linking, removes X11/XKBlib.h includes and XkbGetIndicatorState-based Caps Lock detection from src/main/oshelper.cpp, and makes the fallback branch return false. It also changes the Windows GetKeyState(VK_CAPITAL) check from comparing equality to 1 to masking the low-order toggle bit (0x0001). The change is framed as build cleanup ahead of a Qt6 migration. No memory-safety bug, cryptographic flaw, or privilege escalation is visible in the diff.
Changed components
CMake build configuration (CMakeLists.txt, src/CMakeLists.txt)src/main/oshelper.cpp OSHelper::isCapsLock()Inspect captured patch +4 / −36
diff --git a/CMakeLists.txt b/CMakeLists.txt
index 6c8efa1..67652a0 100644
--- a/CMakeLists.txt
+++ b/CMakeLists.txt
@@ -107,15 +107,6 @@ message(STATUS "libsodium: libraries at ${SODIUM_LIBRARY}")
if(UNIX AND NOT APPLE AND NOT ANDROID)
set(CMAKE_SKIP_RPATH ON)
- set(CMAKE_FIND_LIBRARY_SUFFIXES_PREV ${CMAKE_FIND_LIBRARY_SUFFIXES})
- set(CMAKE_FIND_LIBRARY_SUFFIXES ".so")
- find_package(X11 REQUIRED)
- set(CMAKE_FIND_LIBRARY_SUFFIXES ${CMAKE_FIND_LIBRARY_SUFFIXES_PREV})
- message(STATUS "X11_FOUND = ${X11_FOUND}")
- message(STATUS "X11_INCLUDE_DIR = ${X11_INCLUDE_DIR}")
- message(STATUS "X11_LIBRARIES = ${X11_LIBRARIES}")
- include_directories(${X11_INCLUDE_DIR})
- link_directories(${X11_LIBRARIES})
if(STATIC)
find_library(XCB_LIBRARY xcb)
message(STATUS "Found xcb library: ${XCB_LIBRARY}")
diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt
index b5718df..d29be1c 100644
--- a/src/CMakeLists.txt
+++ b/src/CMakeLists.txt
@@ -104,7 +104,6 @@ target_include_directories(monero-wallet-gui PUBLIC
${CMAKE_CURRENT_SOURCE_DIR}/model
${CMAKE_CURRENT_SOURCE_DIR}/QR-Code-scanner
${CMAKE_CURRENT_SOURCE_DIR}/zxcvbn-c
- ${X11_INCLUDE_DIR}
)
target_compile_definitions(monero-wallet-gui
@@ -138,10 +137,6 @@ target_link_libraries(monero-wallet-gui
zxcvbn
)
-if(X11_FOUND)
- target_link_libraries(monero-wallet-gui ${X11_LIBRARIES})
-endif()
-
if(WITH_SCANNER)
target_link_libraries(monero-wallet-gui qrscanner)
if(LINUX AND NOT ANDROID)
diff --git a/src/main/oshelper.cpp b/src/main/oshelper.cpp
index cb9aca7..5d189ac 100644
--- a/src/main/oshelper.cpp
+++ b/src/main/oshelper.cpp
@@ -53,13 +53,6 @@
#include <windows.h>
#endif
#if defined(Q_OS_LINUX) && !defined(Q_OS_ANDROID)
-#include <X11/XKBlib.h>
-#undef Bool
-#undef KeyPress
-#undef KeyRelease
-#undef FocusIn
-#undef FocusOut
-// #undef those Xlib #defines that conflict with QEvent::Type enum
#include "qt/utils.h"
#endif
@@ -221,26 +214,15 @@ bool OSHelper::removeTemporaryWallet(const QString &fileName) const
return cache_deleted && address_deleted && keys_deleted;
}
-// https://stackoverflow.com/a/3006934
bool OSHelper::isCapsLock() const
{
- // platform dependent method of determining if CAPS LOCK is on
-#if defined(Q_OS_WIN) // MS Windows version
- return GetKeyState(VK_CAPITAL) == 1;
-#elif defined(Q_OS_LINUX) && !defined(Q_OS_ANDROID) // X11 version
- Display * d = XOpenDisplay((char*)0);
- bool caps_state = false;
- if (d) {
- unsigned n;
- XkbGetIndicatorState(d, XkbUseCoreKbd, &n);
- caps_state = (n & 0x01) == 1;
- XCloseDisplay(d);
- }
- return caps_state;
+#if defined(Q_OS_WIN)
+ return (GetKeyState(VK_CAPITAL) & 0x0001) != 0;
#elif defined(Q_OS_MAC)
return MacOSHelper::isCapsLock();
-#endif
+#else
return false;
+#endif
}
QString OSHelper::temporaryPath() const
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.