AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 34 Indexing infrastructure

Add mempool support to /get_address_txs and /feed (#251)

Public commit record

What the developer wrote

Authored by Lee *!* Clagett

73/100 · Adequate
Add mempool support to /get_address_txs and /feed (#251)

Co-authored-by: William Swanson <swansontec@gmail.com>
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit adds mempool (pending transaction) support to Monero Light Wallet Server. It lets users see unconfirmed transactions through the /get_address_txs REST endpoint and the live /feed websocket. The change also refactors how the server checks whether transaction outputs belong to a user's address, moving that logic into a shared helper called ownership_test. There is no direct evidence in the commit message or diff that this fixes a security vulnerability; it reads as a feature addition with associated code cleanup.

Recommended action

Treat this as a feature/refactor commit rather than an urgent security patch. Reviewers should verify that the new mempool cache does not introduce race conditions, that the ownership_test refactor preserves subaddress lookahead and output-deduplication behavior, and that mempool data cannot be used to leak information across accounts. Run the expanded unit tests (mempool.test.cpp, rest.test.cpp, scanner.test.cpp) and consider additional tests for cache eviction and concurrent access.

Security signals we found

01

Large feature commit (+1906/-634) touching REST, WebSocket feed, scanner, and new mempool component

02

Refactored transaction ownership scanning into shared ownership_test helper; reduces duplicated crypto/derivation logic

03

Mempool transactions are parsed and validated before being added to the local cache in /submit_raw_tx

04

Mempool cache uses mutex-guarded state and immutable snapshots for concurrent readers

05

Address cache for negative mempool matches is bounded (max 1000 entries) to limit memory growth

06

No explicit security claim, CVE, or advisory referenced in commit or supplied materials

Risk score

Why this scored 34/100

Our methodology →
Potential impact 5/30
Exploitability 5/25
Stealth signal 5/15
Affected reach 10/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.