core: fix npe setting proxy with daemon connection
What changed, and why it matters
This is a one-line bug fix for a NullPointerException (NPE) in the Java Monero wallet library. Before the fix, the code tried to read a proxy setting from a connection object without first checking whether the connection object existed. If no daemon connection was provided, the program would crash. The fix adds a simple null check. It is a defensive coding fix, not an obvious security vulnerability, though unhandled crashes can sometimes be abused to deny service or mask other behavior.
Treat as a routine stability/defensive fix. Review whether callers can pass a null connection from untrusted input and ensure the resulting behavior (empty proxy parameter) is intentional. No urgent security response is indicated by the diff alone.
Security signals we found
NullPointerException crash path removed
Incomplete null guard on user-supplied connection object
Defensive fix in RPC wallet connection setup
Evidence from the diff
In MoneroWalletRpc.java, the setDaemonConnection logic dereferenced connection.getProxyUri() before verifying connection was non-null. The patch changes the guard from if (connection.getProxyUri() == null) to if (connection == null || connection.getProxyUri() == null), preventing a NullPointerException when connection is null. The else branch already contained a ternary handling connection == null, suggesting the null case was intended but the guard was incomplete.
Changed components
src/main/java/monero/wallet/MoneroWalletRpc.javasetDaemonConnection proxy validation logicInspect captured patch +1 / −1
diff --git a/src/main/java/monero/wallet/MoneroWalletRpc.java b/src/main/java/monero/wallet/MoneroWalletRpc.java
index b614ee4..8b4a96b 100644
--- a/src/main/java/monero/wallet/MoneroWalletRpc.java
+++ b/src/main/java/monero/wallet/MoneroWalletRpc.java
@@ -513,7 +513,7 @@ public class MoneroWalletRpc extends MoneroWalletDefault {
params.put("ssl_allow_any_cert", sslOptions.getAllowAnyCert());
// set proxy which must match startup proxy if applicable
- if (connection.getProxyUri() == null) {
+ if (connection == null || connection.getProxyUri() == null) {
if (startupProxyUri != null) throw new MoneroError("Cannot set daemon connection without proxy URI because monero-wallet-rpc was started with a proxy URI: " + startupProxyUri);
} else {
if (startupProxyUri == null) params.put("proxy", connection == null ? "" : connection.getProxyUri());
Why this scored 22/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.