What changed, and why it matters
This commit changes the Tor privacy service in Stack Wallet so that only one instance of the service is created and reused, rather than creating a fresh one each time. This is a code-quality and reliability fix. It does not by itself fix a known exploit, but running multiple Tor service instances could previously have caused inconsistent privacy states, resource waste, or subtle bugs that might weaken privacy guarantees.
Treat as a minor defensive hardening change. Review whether any code paths relied on fresh Tor service instances, and verify that the singleton lifecycle correctly handles reconnection, cleanup, and error states. No urgent patching is indicated by the diff alone.
Security signals we found
singleton pattern applied to privacy-critical Tor service
previously each call created a new Tor service instance
potential for inconsistent Tor connection state or duplicate resources before fix
no explicit security wording in commit title or message
Evidence from the diff
The patch converts _TorServiceImpl and _FusionTorServiceImpl from repeatedly instantiable classes into singletons via a private constructor and a static instance getter. The factory functions _getInterface() and _getFusionInterface() now return the singleton instance. The diff is small and only touches a template file used to generate the Tor service implementation. There is no explicit security claim, CVE, or researcher attribution in the commit.
Changed components
tool/wl_templates/TOR_tor_service_impl.template.dartTorService implementationFusionTorService implementationInspect captured patch +13 / −2
diff --git a/tool/wl_templates/TOR_tor_service_impl.template.dart b/tool/wl_templates/TOR_tor_service_impl.template.dart
index 3e26caf..63ee6ef 100644
--- a/tool/wl_templates/TOR_tor_service_impl.template.dart
+++ b/tool/wl_templates/TOR_tor_service_impl.template.dart
@@ -21,10 +21,15 @@ FusionTorService _getFusionInterface() => throw Exception("TOR not enabled!");
//END_OFF
//ON
-TorService _getInterface() => _TorServiceImpl();
-FusionTorService _getFusionInterface() => _FusionTorServiceImpl();
+TorService _getInterface() => _TorServiceImpl.instance;
+FusionTorService _getFusionInterface() => _FusionTorServiceImpl.instance;
class _TorServiceImpl extends TorService {
+ static _TorServiceImpl? _instance;
+ static _TorServiceImpl get instance => _instance ??= _TorServiceImpl._();
+
+ _TorServiceImpl._();
+
Tor? _tor;
String? _torDataDirPath;
TorConnectionStatus _status = TorConnectionStatus.disconnected;
@@ -131,6 +136,12 @@ class _TorServiceImpl extends TorService {
}
class _FusionTorServiceImpl extends FusionTorService {
+ static _FusionTorServiceImpl? _instance;
+ static _FusionTorServiceImpl get instance =>
+ _instance ??= _FusionTorServiceImpl._();
+
+ _FusionTorServiceImpl._();
+
Tor? _tor;
String? _torDataDirPath;
Why this scored 27/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.