Don't log MDB_NOTFOUND with subaddress lookup (#208)
What changed, and why it matters
This change stops the program from writing a scary but harmless 'not found' log message when a subaddress lookup returns no result. It is a minor cleanup that reduces log noise; it does not fix a vulnerability that an attacker could exploit.
No security action required. Treat as routine code-quality/logging improvement.
Security signals we found
Log-noise reduction for expected LMDB MDB_NOTFOUND result
No change to error handling paths other than suppressing one log line
No input validation, authorization, or cryptographic changes
Evidence from the diff
The patch modifies a subaddress lookup in src/db/storage.cpp. Previously, mdb_cursor_get with MDB_GET_BOTH was wrapped in MLWS_LMDB_CHECK, which logs every non-zero LMDB error including MDB_NOTFOUND. The new code checks the return code explicitly and returns lmdb::error(MDB_NOTFOUND) without logging when the key/value pair is absent. This is expected behavior for a lookup that may legitimately miss, so the only effect is suppressing an unnecessary log line. No access-control, cryptographic, or data-integrity behavior changes.
Changed components
src/db/storage.cpp: subaddress lookup functionInspect captured patch +7 / −1
diff --git a/src/db/storage.cpp b/src/db/storage.cpp
index 6bb7813..509e96d 100644
--- a/src/db/storage.cpp
+++ b/src/db/storage.cpp
@@ -1087,7 +1087,13 @@ namespace db
MDB_val key = lmdb::to_val(id);
MDB_val value = lmdb::to_val(address);
- MLWS_LMDB_CHECK(mdb_cursor_get(cur.get(), &key, &value, MDB_GET_BOTH));
+ const int err = mdb_cursor_get(cur.get(), &key, &value, MDB_GET_BOTH);
+ if (err)
+ {
+ if (err != MDB_NOTFOUND)
+ return log_lmdb_error(err, __LINE__, __FILE__);
+ return {lmdb::error(err)}; // do not log MDB_NOTFOUND; expected
+ }
return subaddress_indexes.get_value<MONERO_FIELD(subaddress_map, index)>(value);
}
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.