What changed, and why it matters
This commit fixes a database cleanup routine that deletes a wallet's blockchain data (transactions, addresses, and unspent coins). Previously, the code counted records outside of the write transaction, then opened a transaction to delete them. If data changed between the count and the deletion, the loop logic could behave incorrectly. The fix moves the counts inside the same write transaction and increases the batch size from 50 to 100. There is no claim in the commit that this is a security fix, and no public references tie it to an incident.
Review whether deleteWalletBlockchainData is used during wallet deletion or cache reset, and verify that moving counts inside the write transaction fully resolves any inconsistency. Consider adding unit tests that simulate concurrent additions during deletion. Treat as a routine correctness fix unless further evidence links it to data-loss or security issues.
Security signals we found
Database transaction boundary corrected
Potential TOCTOU between count and delete operations removed
No explicit security claim in commit message or diff
No tests or advisory references supplied
Evidence from the diff
The change moves the transactionCount, transactionCountV2, addressCount, and utxoCount queries inside the isar.writeTxn(…) block in deleteWalletBlockchainData. Previously these counts were performed before the transaction began, creating a read-modify-write style window where the counts could be stale relative to the deletions. Additionally, paginateLimit was raised from 50 to 100. The diff is small and does not include tests, advisory text, or CVE metadata. The security relevance is speculative: stale counts in a paginated deletion loop could lead to incomplete deletion or unexpected iteration behavior, but no direct exploit path is demonstrated.
Changed components
lib/db/isar/main_db.dartdeleteWalletBlockchainData methodIsar database transaction handlingInspect captured patch +9 / −11
diff --git a/lib/db/isar/main_db.dart b/lib/db/isar/main_db.dart
index 6a4613e..9e7e0da 100644
--- a/lib/db/isar/main_db.dart
+++ b/lib/db/isar/main_db.dart
@@ -447,18 +447,16 @@ class MainDB {
//
Future<void> deleteWalletBlockchainData(String walletId) async {
- final transactionCount = await getTransactions(walletId).count();
- final transactionCountV2 = await isar.transactionV2s
- .where()
- .walletIdEqualTo(walletId)
- .count();
- final addressCount = await getAddresses(walletId).count();
- final utxoCount = await getUTXOs(walletId).count();
- // final lelantusCoinCount =
- // await isar.lelantusCoins.where().walletIdEqualTo(walletId).count();
-
await isar.writeTxn(() async {
- const paginateLimit = 50;
+ final transactionCount = await getTransactions(walletId).count();
+ final transactionCountV2 = await isar.transactionV2s
+ .where()
+ .walletIdEqualTo(walletId)
+ .count();
+ final addressCount = await getAddresses(walletId).count();
+ final utxoCount = await getUTXOs(walletId).count();
+
+ const paginateLimit = 100;
// transactions
for (int i = 0; i < transactionCount; i += paginateLimit) {
Why this scored 29/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.