provide workaround for monero-wallet-rpc ‘stop_wallet’ authorization failure regression

This commit is contained in:
The MMGen Project 2026-09-17 16:00:13 +00:00
commit 97b7305d0b
Signed by: mmgen
GPG key ID: 3F8B1861E32B7DA2
6 changed files with 19 additions and 4 deletions

View file

@ -45,6 +45,7 @@ class Daemon(Lockable):
new_console_mswin = False
lockfile = None
private_port = None
disable_authentication = False
avail_opts = ()
avail_flags = () # like opts, but can be set or unset after instantiation
_reset_ok = ('debug', 'wait', 'pids')

View file

@ -1 +1 @@
16.3.0dev8
16.3.0dev9

View file

@ -109,6 +109,7 @@ class MoneroWalletDaemon(RPCDaemon):
proxy = None,
port_shift = None,
datadir = None,
disable_authentication = False,
trust_monerod = False,
test_monerod = False,
**kwargs):
@ -120,6 +121,7 @@ class MoneroWalletDaemon(RPCDaemon):
self.network = proto.network
self.wallet_dir = wallet_dir or (self.test_suite_datadir if self.test_suite else None)
self.rpc_port = getattr(self.rpc_ports, self.network) + (11 if self.test_suite else 0)
self.disable_authentication = disable_authentication
if port_shift:
self.rpc_port += port_shift
@ -158,12 +160,13 @@ class MoneroWalletDaemon(RPCDaemon):
"the MMGen config file.")
self.daemon_args = list_gen(
['--disable-rpc-login', self.disable_authentication],
['--trusted-daemon', trust_monerod],
['--untrusted-daemon', not trust_monerod],
[f'--rpc-bind-port={self.rpc_port}'],
[f'--wallet-dir={self.wallet_dir}'],
[f'--log-file={self.logfile}'],
[f'--rpc-login={self.user}:{self.passwd}'],
[f'--rpc-login={self.user}:{self.passwd}', not self.disable_authentication],
[f'--daemon-address={self.monerod_addr}', self.monerod_addr],
[f'--daemon-port={self.monerod_port}', not self.monerod_addr],
[f'--proxy={self.proxy}', self.proxy],

View file

@ -149,7 +149,11 @@ class MoneroWalletRPCClient(MoneroRPCClient):
ymsg('Wallet daemon hung up unexpectedly, killing process just in case')
else:
ymsg(f'{type(e).__name__}: {e}')
except Exception:
ymsg('Unable to shut down wallet daemon gracefully, so killing process instead')
except Exception as e:
# Included for completeness: with ‘disable_authentication’ in effect, we shouldn’t be here:
if 'unauthorized' in str(e).lower():
ymsg('Unable to shut down wallet daemon gracefully, so killing process instead')
else:
ymsg(f'{type(e).__name__}: {e}')
return self.daemon.stop(silent=True)

View file

@ -28,6 +28,11 @@ from .wallet import OpWallet
class OpSubmit(OpWallet):
action = 'submitting transaction with'
opts = ('tx_relay_daemon',)
# The following is a workaround for a monero-wallet-rpc authorization failure regression
# with the ‘stop_wallet’ command. Authentication to send a signed transaction is overkill
# in any case: if an attacker has access to the online machine, and hence the transaction,
# they can broadcast it to the network by some other means.
disable_authentication = True # FIXME
def post_mount_action(self):
return self.tx # trigger an exit if no suitable transaction present

View file

@ -37,6 +37,7 @@ class OpWallet(OpBase):
wallet_offline = False
start_daemon = True
skip_wallet_check = False # for debugging
disable_authentication = False
def __init__(self, cfg, uarg_tuple):
@ -67,6 +68,7 @@ class OpWallet(OpBase):
proto = self.proto,
wallet_dir = self.cfg.wallet_dir or '.',
monerod_addr = self.cfg.daemon or None,
disable_authentication = self.disable_authentication,
trust_monerod = self.trust_monerod,
test_monerod = not self.wallet_offline)