remove the redundant merkle proof flag from the cormorant server capability
What changed, and why it matters
This commit removes a special flag telling Sparrow not to request cryptographic transaction proofs when connected to a backend called 'cormorant'. The change makes cormorant behave like other local-node backends, which is described as removing a redundant distinction. It is a small cleanup with no obvious security bug being fixed.
Treat as a routine refactor. If reviewing for security, verify that cormorant-backed setups still correctly skip redundant merkle-proof verification when the backend is the user's own node, and that the default ServerCapability flags are appropriate for cormorant.
Security signals we found
Change touches server capability / transaction verification logic
Removes a previously special-cased merkle-proof flag for one backend
No explicit security language in commit title or message
No advisory, CVE, or researcher attribution present in commit
Evidence from the diff
The patch removes .withMerkleProofs(false) from the ServerCapability returned for servers whose version starts with ‘cormorant’. It also trims the explanatory comment in isVerifyingTransactions() that discussed cormorant vs. bwt behavior, and removes a related test comment. The functional effect is that cormorant is no longer singled out as a server that cannot provide merkle proofs; it now uses the default capability flags. This appears to be a code simplification rather than a vulnerability fix.
Changed components
src/main/java/com/sparrowwallet/sparrow/net/ElectrumServer.javasrc/test/java/com/sparrowwallet/sparrow/net/ElectrumServerTest.javaInspect captured patch +2 / −4
### src/main/java/com/sparrowwallet/sparrow/net/ElectrumServer.java
@@ -1821,8 +1821,7 @@ static List<BlockHeader> getLinkedHeaders(BlockHeaders chunk, int count, Sha256H
* in the wallet no more than any other the server cannot prove. A tip not yet announced is not evidence of lagging.
* <p>
* Not asked of a Bitcoin Core connection at all, whichever backend is fronting it: the node answering is the user's own, and a proof it built
- * against headers it also supplied establishes nothing it has not already been trusted for. Cormorant declares as much in its capability, but
- * bwt takes over where cormorant cannot start, and the same node should not verify or not according to which one did.
+ * against headers it also supplied establishes nothing it has not already been trusted for.
*/
public static boolean isVerifyingTransactions() {
if(!Config.get().isVerifyTransactions() || Config.get().getServerType() == ServerType.BITCOIN_CORE
@@ -2966,7 +2965,7 @@ public static ServerCapability getServerCapability(List<String> serverVersion) {
}
if(server.startsWith("cormorant")) {
- return new ServerCapability(true, false, true, false, true).withMerkleProofs(false);
+ return new ServerCapability(true, false, true, false, true);
}
if(server.startsWith("electrs/")) {
### src/test/java/com/sparrowwallet/sparrow/net/ElectrumServerTest.java
@@ -355,7 +355,6 @@ public void doesNotVerifyAgainstTheUsersOwnNode() {
ServerCapability previousCapability = ElectrumServer.serverCapability;
ServerType previousServerType = Config.get().getServerType();
try {
- //The capability bwt falls through to, which unlike cormorant's says nothing about proofs
ElectrumServer.serverCapability = new ServerCapability(false, true, true);
assertTrue(ElectrumServer.serverCapability.supportsMerkleProofs());
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.