support flag to skip refresh after multisig import
What changed, and why it matters
This commit adds a new optional flag to the Monero wallet's multisig import function, letting callers choose whether the wallet automatically refreshes after importing multisig data. It is a straightforward API enhancement that preserves the previous default behavior (refresh enabled). There is no indication in the commit that this fixes a security bug or vulnerability.
No security action required; review as normal feature/API change. If the project exposes this library to untrusted callers, ensure the new flag is documented so integrators understand the trade-off of skipping refresh.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The change threads a boolean refresh_after_import parameter through the Java interface, default implementation, JNI bridge, and RPC wrapper for importMultisigHex. Existing callers continue to refresh by default, while new callers can skip the refresh. The RPC path now passes refresh_after_import to the underlying Monero wallet RPC. No bounds checks, memory handling, or cryptographic operations are modified beyond passing the flag.
Changed components
src/main/cpp/monero_jni_bridge.cppsrc/main/cpp/monero_jni_bridge.hsrc/main/java/monero/wallet/MoneroWallet.javasrc/main/java/monero/wallet/MoneroWalletDefault.javasrc/main/java/monero/wallet/MoneroWalletFull.javasrc/main/java/monero/wallet/MoneroWalletRpc.javaInspect captured patch +23 / −8
diff --git a/src/main/cpp/monero_jni_bridge.cpp b/src/main/cpp/monero_jni_bridge.cpp
index bd620b4..101f82d 100644
--- a/src/main/cpp/monero_jni_bridge.cpp
+++ b/src/main/cpp/monero_jni_bridge.cpp
@@ -2076,7 +2076,7 @@ JNIEXPORT jstring JNICALL Java_monero_wallet_MoneroWalletFull_exportMultisigHexJ
}
}
-JNIEXPORT jint JNICALL Java_monero_wallet_MoneroWalletFull_importMultisigHexJni(JNIEnv* env, jobject instance, jobjectArray jmultisig_hexes) {
+JNIEXPORT jint JNICALL Java_monero_wallet_MoneroWalletFull_importMultisigHexJni(JNIEnv* env, jobject instance, jobjectArray jmultisig_hexes, jboolean refresh_after_import) {
MTRACE("Java_monero_wallet_MoneroWalletFull_importMultisigHexJni");
// get peer multisig hex as vector<string>
@@ -2097,7 +2097,7 @@ JNIEXPORT jint JNICALL Java_monero_wallet_MoneroWalletFull_importMultisigHexJni(
// import peer multisig hex and return the number of outputs they signed
monero_wallet* wallet = get_handle<monero_wallet>(env, instance, JNI_WALLET_HANDLE);
try {
- int num_outputs = wallet->import_multisig_hex(multisig_hexes);
+ int num_outputs = wallet->import_multisig_hex(multisig_hexes, refresh_after_import);
return num_outputs;
} catch (...) {
rethrow_cpp_exception_as_java_exception(env);
diff --git a/src/main/cpp/monero_jni_bridge.h b/src/main/cpp/monero_jni_bridge.h
index ed25ca8..aa4e84c 100644
--- a/src/main/cpp/monero_jni_bridge.h
+++ b/src/main/cpp/monero_jni_bridge.h
@@ -255,7 +255,7 @@ JNIEXPORT jstring JNICALL Java_monero_wallet_MoneroWalletFull_exchangeMultisigKe
JNIEXPORT jstring JNICALL Java_monero_wallet_MoneroWalletFull_exportMultisigHexJni(JNIEnv *, jobject);
-JNIEXPORT jint JNICALL Java_monero_wallet_MoneroWalletFull_importMultisigHexJni(JNIEnv *, jobject, jobjectArray);
+JNIEXPORT jint JNICALL Java_monero_wallet_MoneroWalletFull_importMultisigHexJni(JNIEnv *, jobject, jobjectArray, jboolean);
JNIEXPORT jstring JNICALL Java_monero_wallet_MoneroWalletFull_signMultisigTxHexJni(JNIEnv *, jobject, jstring);
diff --git a/src/main/java/monero/wallet/MoneroWallet.java b/src/main/java/monero/wallet/MoneroWallet.java
index a6a2a8d..3ddbc21 100644
--- a/src/main/java/monero/wallet/MoneroWallet.java
+++ b/src/main/java/monero/wallet/MoneroWallet.java
@@ -1337,7 +1337,7 @@ public interface MoneroWallet {
* @return the number of outputs signed with the given multisig hex
*/
public int importMultisigHex(String... multisigHexes);
-
+
/**
* Import multisig info as hex from other participants.
*
@@ -1346,6 +1346,15 @@ public interface MoneroWallet {
*/
public int importMultisigHex(List<String> multisigHexes);
+ /**
+ * Import multisig info as hex from other participants.
+ *
+ * @param multisigHexes are multisig hex from each participant
+ * @param refreshAfterImport specifies if the wallet should be refreshed after importing
+ * @return the number of outputs signed with the given multisig hex
+ */
+ public int importMultisigHex(List<String> multisigHexes, boolean refreshAfterImport);
+
/**
* Sign multisig transactions from a multisig wallet.
*
diff --git a/src/main/java/monero/wallet/MoneroWalletDefault.java b/src/main/java/monero/wallet/MoneroWalletDefault.java
index 0dbbc54..4ec0496 100644
--- a/src/main/java/monero/wallet/MoneroWalletDefault.java
+++ b/src/main/java/monero/wallet/MoneroWalletDefault.java
@@ -444,6 +444,11 @@ abstract class MoneroWalletDefault implements MoneroWallet {
public int importMultisigHex(String... multisigHexes) {
return importMultisigHex(Arrays.asList(multisigHexes));
}
+
+ @Override
+ public int importMultisigHex(List<String> multisigHexes) {
+ return importMultisigHex(multisigHexes, true);
+ }
@Override
public void close() {
diff --git a/src/main/java/monero/wallet/MoneroWalletFull.java b/src/main/java/monero/wallet/MoneroWalletFull.java
index 728052d..13a275a 100644
--- a/src/main/java/monero/wallet/MoneroWalletFull.java
+++ b/src/main/java/monero/wallet/MoneroWalletFull.java
@@ -1326,10 +1326,10 @@ public class MoneroWalletFull extends MoneroWalletDefault {
}
@Override
- public int importMultisigHex(List<String> multisigHexes) {
+ public int importMultisigHex(List<String> multisigHexes, boolean refreshAfterImport) {
assertNotClosed();
try {
- return importMultisigHexJni(multisigHexes.toArray(new String[multisigHexes.size()]));
+ return importMultisigHexJni(multisigHexes.toArray(new String[multisigHexes.size()]), refreshAfterImport);
} catch (Exception e) {
throw new MoneroError(e.getMessage());
}
@@ -1591,7 +1591,7 @@ public class MoneroWalletFull extends MoneroWalletDefault {
private native String exportMultisigHexJni();
- private native int importMultisigHexJni(String[] multisigHexes);
+ private native int importMultisigHexJni(String[] multisigHexes, boolean refreshAfterImport);
private native String signMultisigTxHexJni(String multisigTxHex);
diff --git a/src/main/java/monero/wallet/MoneroWalletRpc.java b/src/main/java/monero/wallet/MoneroWalletRpc.java
index 8b4a96b..7a13f0f 100644
--- a/src/main/java/monero/wallet/MoneroWalletRpc.java
+++ b/src/main/java/monero/wallet/MoneroWalletRpc.java
@@ -1883,9 +1883,10 @@ public class MoneroWalletRpc extends MoneroWalletDefault {
@Override
@SuppressWarnings("unchecked")
- public int importMultisigHex(List<String> multisigHexes) {
+ public int importMultisigHex(List<String> multisigHexes, boolean refreshAfterImport) {
Map<String, Object> params = new HashMap<String, Object>();
params.put("info", multisigHexes);
+ params.put("refresh_after_import", refreshAfterImport);
Map<String, Object> resp = rpc.sendJsonRequest("import_multisig_info", params);
Map<String, Object> result = (Map<String, Object>) resp.get("result");
return ((BigInteger) result.get("n_outputs")).intValue();
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.