set missing pool attribute to fix filtered data
What changed, and why it matters
This is a one-line bug fix in a Java library that talks to the Monero cryptocurrency wallet. The developer added a missing setting that marks confirmed transactions as no longer being in the memory pool (the waiting area for unconfirmed transactions). Without this setting, filters that ask 'show me only transactions still in the pool' could include already-confirmed transactions by mistake, leading to confusing or incorrect wallet data. There is no direct security attack shown in the commit itself.
Treat as a normal functional bug fix. Reviewers may optionally verify that other boolean fields on MoneroTxWallet are consistently initialized and that pool/confirmed filters behave correctly after the change. No urgent security response is indicated by this commit alone.
Security signals we found
Data-integrity bug: missing object initialization leads to incorrect filter results
No input validation, injection, cryptographic, or authentication change present
No memory-unsafe code or unsafe deserialization introduced
Evidence from the diff
In MoneroWalletRpc.java, when deserializing a confirmed on-chain transaction into a MoneroTxWallet object, the code now explicitly calls tx.setInTxPool(false). Previously this boolean was left at its default/unset state. Because the library uses this flag to filter transaction lists, leaving it unset caused pool-filtered queries to return incorrect results. The change is purely a data-integrity fix; no input validation, cryptography, RPC authentication, or memory-safety issue is addressed.
Changed components
src/main/java/monero/wallet/MoneroWalletRpc.javaMoneroTxWallet transaction deserialization/pooling logicInspect captured patch +1 / −0
diff --git a/src/main/java/monero/wallet/MoneroWalletRpc.java b/src/main/java/monero/wallet/MoneroWalletRpc.java
index 4129314..b614ee4 100644
--- a/src/main/java/monero/wallet/MoneroWalletRpc.java
+++ b/src/main/java/monero/wallet/MoneroWalletRpc.java
@@ -3092,6 +3092,7 @@ public class MoneroWalletRpc extends MoneroWalletDefault {
// initialize tx
MoneroTxWallet tx = new MoneroTxWallet();
tx.setIsConfirmed(true);
+ tx.setInTxPool(false);
tx.setIsRelayed(true);
tx.setIsFailed(false);
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.