AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 39 Indexing infrastructure

Add support for subaddress lookahead (#195)

Public commit record

What the developer wrote

Authored by Lee *!* Clagett

53/100 · Thin
Add support for subaddress lookahead (#195)
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
The short version

What changed, and why it matters

This commit adds subaddress lookahead support to the Monero Light Wallet Server (LWS). It lets wallets tell the server how many future subaddresses to precompute and watch, replacing a simple on/off subaddress flag with a configurable limit. The change touches the database format, admin and REST APIs, and the block scanner. It also adds automatic approval options for account creation and import requests. There is no explicit security bug visible in the diff, but the large schema migration and new resource-limit logic introduce ordinary operational risks: a misconfigured or maliciously large lookahead could make the server precompute huge numbers of subaddresses, consuming CPU and database space. The code does add a max_subaddresses cap and clamping helpers to mitigate this.

Recommended action

Treat this as a significant feature commit rather than a confirmed vulnerability. Reviewers should verify: (1) the LMDB migration correctly handles existing v0 tables and does not corrupt records; (2) all lookahead arithmetic is bounded by max_subaddresses and cannot overflow; (3) auto_accept_import/auto_accept_creation do not bypass intended admin approval workflows in production deployments; (4) the scanner's reactive update_lookahead cannot be triggered repeatedly to exhaust resources. No immediate patch is indicated, but operators should set conservative max_subaddresses limits and monitor DB growth.

Security signals we found

01

New resource-limit parameter max_subaddresses introduced across admin, REST, storage, and scanner layers

02

Database schema migration from v0 to v1 for account and request_info tables

03

Automatic acceptance options added for both account creation and account import (auto_accept_creation, auto_accept_import)

04

Lookahead failure state stored in account.lookahead_fail and exposed via REST responses

05

Integer overflow mitigation via add_and_clamp helper and explicit max_subaddresses checks

06

Subaddress pre-derivation now triggered both at account creation/import and reactively during block scanning

Risk score

Why this scored 39/100

Our methodology →
Potential impact 8/30
Exploitability 7/25
Stealth signal 6/15
Affected reach 9/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.