AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 56 Indexing infrastructure

Fix `MDB_BAD_RSLOT` in `subaddress_reader::update_reader()` causing permanently missed subaddress outputs (#278)

Public commit record

What the developer wrote

Authored by Evgeny

58/100 · Thin
Fix `MDB_BAD_RSLOT` in `subaddress_reader::update_reader()` causing permanently missed subaddress outputs (#278)

* fix: regtest
* fix: MDB_BAD_RSLOT
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a database-handling bug in Monero Light Wallet Server (LWS). The bug caused the server to permanently miss some subaddress outputs because a read transaction was not closed before a new one was opened, triggering an LMDB error (MDB_BAD_RSLOT). The fix explicitly releases the old read transaction before starting the next one. There is no direct evidence this is exploitable by an attacker; it appears to be a reliability/correctness bug.

Recommended action

Apply the patch. Monitor for any remaining LMDB transaction-lifetime issues in `subaddress_reader` and related readers. Consider adding regression tests that exercise repeated `update_reader()` calls under LMDB default settings.

Security signals we found

01

Fixes LMDB transaction-slot error (MDB_BAD_RSLOT)

02

Prevents permanently missed subaddress outputs

03

Changes test expectations to reflect recovered output

04

Adds regtest flag propagation in server startup

Risk score

Why this scored 56/100

Our methodology →
Potential impact 18/30
Exploitability 5/25
Stealth signal 12/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.