AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 35 Indexing infrastructure

Fix mempool webhook read during subaddress scanning (#283)

Public commit record

What the developer wrote

Authored by Lee *!* Clagett

58/100 · Thin
Fix mempool webhook read during subaddress scanning (#283)
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a bug in the Monero Light Wallet Server (LWS) where webhook notifications for mempool transactions could fail or behave incorrectly when scanning subaddresses. The change passes an existing database reader into the output-handling callback, so the code no longer tries to start a new read transaction inside an already-active one. This prevents potential failures or inconsistent reads during mempool webhook processing. The commit also adds tests that exercise the mempool publication path with a webhook server.

Recommended action

Treat as a routine bug-fix patch. Reviewers should verify that all output-action call sites now pass a valid reader when one is available, and that the new unit test exercises both the reader-reuse and reader-null code paths. No immediate security response appears necessary unless missed webhooks are considered a critical availability issue for downstream services.

Security signals we found

01

Fixes a read-transaction lifecycle issue in webhook lookup during mempool scanning

02

Adds regression test covering mempool publication + webhook delivery

03

Callback signature change propagates an existing storage_reader to avoid nested/duplicate reads

04

Potential for missed or duplicate webhook events if reader state was inconsistent (bug class: correctness / availability)

Risk score

Why this scored 35/100

Our methodology →
Potential impact 8/30
Exploitability 6/25
Stealth signal 5/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.