Clean up RPCs that are disabled in safe-mode.

This removes some inconsistencies in what worked and didn't work in
 safemode. Now only RPCs involved in getting balances or sending
 funds are disabled.

Previously you could mine but not submit blocks— but we may need more
 blocks to resolve a fork that triggered safe mode in the first place,
 and the non-submission was not reliable since some miners submit
 blocks via multiple means. There were also a number of random commands
 disabled that had nothing to do with the blockchain like verifymessage.

Thanks to earlz for pointing out that there were some moderately cheap
 ways to maliciously trigger safe mode, which brought attention to
 the fact that safemode wasn't used in a very intelligent way.
This commit is contained in:
Gregory Maxwell 2014-07-10 10:06:43 -07:00
parent f2286a69a9
commit b60be6be4a

View File

@ -232,8 +232,8 @@ static const CRPCCommand vRPCCommands[] =
{ "getblockchaininfo", &getblockchaininfo, true, false, false }, { "getblockchaininfo", &getblockchaininfo, true, false, false },
{ "getbestblockhash", &getbestblockhash, true, false, false }, { "getbestblockhash", &getbestblockhash, true, false, false },
{ "getblockcount", &getblockcount, true, false, false }, { "getblockcount", &getblockcount, true, false, false },
{ "getblock", &getblock, false, false, false }, { "getblock", &getblock, true, false, false },
{ "getblockhash", &getblockhash, false, false, false }, { "getblockhash", &getblockhash, true, false, false },
{ "getdifficulty", &getdifficulty, true, false, false }, { "getdifficulty", &getdifficulty, true, false, false },
{ "getrawmempool", &getrawmempool, true, false, false }, { "getrawmempool", &getrawmempool, true, false, false },
{ "gettxout", &gettxout, true, false, false }, { "gettxout", &gettxout, true, false, false },
@ -245,32 +245,32 @@ static const CRPCCommand vRPCCommands[] =
{ "getmininginfo", &getmininginfo, true, false, false }, { "getmininginfo", &getmininginfo, true, false, false },
{ "getnetworkhashps", &getnetworkhashps, true, false, false }, { "getnetworkhashps", &getnetworkhashps, true, false, false },
{ "prioritisetransaction", &prioritisetransaction, true, false, false }, { "prioritisetransaction", &prioritisetransaction, true, false, false },
{ "submitblock", &submitblock, false, true, false }, { "submitblock", &submitblock, true, true, false },
/* Raw transactions */ /* Raw transactions */
{ "createrawtransaction", &createrawtransaction, false, false, false }, { "createrawtransaction", &createrawtransaction, true, false, false },
{ "decoderawtransaction", &decoderawtransaction, false, false, false }, { "decoderawtransaction", &decoderawtransaction, true, false, false },
{ "decodescript", &decodescript, false, false, false }, { "decodescript", &decodescript, true, false, false },
{ "getrawtransaction", &getrawtransaction, false, false, false }, { "getrawtransaction", &getrawtransaction, true, false, false },
{ "sendrawtransaction", &sendrawtransaction, false, false, false }, { "sendrawtransaction", &sendrawtransaction, false, false, false },
{ "signrawtransaction", &signrawtransaction, false, false, false }, /* uses wallet if enabled */ { "signrawtransaction", &signrawtransaction, false, false, false }, /* uses wallet if enabled */
/* Utility functions */ /* Utility functions */
{ "createmultisig", &createmultisig, true, true , false }, { "createmultisig", &createmultisig, true, true , false },
{ "validateaddress", &validateaddress, true, false, false }, /* uses wallet if enabled */ { "validateaddress", &validateaddress, true, false, false }, /* uses wallet if enabled */
{ "verifymessage", &verifymessage, false, false, false }, { "verifymessage", &verifymessage, true, false, false },
{ "estimatefee", &estimatefee, true, true, false }, { "estimatefee", &estimatefee, true, true, false },
{ "estimatepriority", &estimatepriority, true, true, false }, { "estimatepriority", &estimatepriority, true, true, false },
#ifdef ENABLE_WALLET #ifdef ENABLE_WALLET
/* Wallet */ /* Wallet */
{ "addmultisigaddress", &addmultisigaddress, false, false, true }, { "addmultisigaddress", &addmultisigaddress, true, false, true },
{ "backupwallet", &backupwallet, true, false, true }, { "backupwallet", &backupwallet, true, false, true },
{ "dumpprivkey", &dumpprivkey, true, false, true }, { "dumpprivkey", &dumpprivkey, true, false, true },
{ "dumpwallet", &dumpwallet, true, false, true }, { "dumpwallet", &dumpwallet, true, false, true },
{ "encryptwallet", &encryptwallet, false, false, true }, { "encryptwallet", &encryptwallet, true, false, true },
{ "getaccountaddress", &getaccountaddress, true, false, true }, { "getaccountaddress", &getaccountaddress, true, false, true },
{ "getaccount", &getaccount, false, false, true }, { "getaccount", &getaccount, true, false, true },
{ "getaddressesbyaccount", &getaddressesbyaccount, true, false, true }, { "getaddressesbyaccount", &getaddressesbyaccount, true, false, true },
{ "getbalance", &getbalance, false, false, true }, { "getbalance", &getbalance, false, false, true },
{ "getnewaddress", &getnewaddress, true, false, true }, { "getnewaddress", &getnewaddress, true, false, true },
@ -279,10 +279,10 @@ static const CRPCCommand vRPCCommands[] =
{ "getreceivedbyaddress", &getreceivedbyaddress, false, false, true }, { "getreceivedbyaddress", &getreceivedbyaddress, false, false, true },
{ "gettransaction", &gettransaction, false, false, true }, { "gettransaction", &gettransaction, false, false, true },
{ "getunconfirmedbalance", &getunconfirmedbalance, false, false, true }, { "getunconfirmedbalance", &getunconfirmedbalance, false, false, true },
{ "getwalletinfo", &getwalletinfo, true, false, true }, { "getwalletinfo", &getwalletinfo, false, false, true },
{ "importprivkey", &importprivkey, false, false, true }, { "importprivkey", &importprivkey, true, false, true },
{ "importwallet", &importwallet, false, false, true }, { "importwallet", &importwallet, true, false, true },
{ "importaddress", &importaddress, false, false, true }, { "importaddress", &importaddress, true, false, true },
{ "keypoolrefill", &keypoolrefill, true, false, true }, { "keypoolrefill", &keypoolrefill, true, false, true },
{ "listaccounts", &listaccounts, false, false, true }, { "listaccounts", &listaccounts, false, false, true },
{ "listaddressgroupings", &listaddressgroupings, false, false, true }, { "listaddressgroupings", &listaddressgroupings, false, false, true },
@ -292,16 +292,16 @@ static const CRPCCommand vRPCCommands[] =
{ "listsinceblock", &listsinceblock, false, false, true }, { "listsinceblock", &listsinceblock, false, false, true },
{ "listtransactions", &listtransactions, false, false, true }, { "listtransactions", &listtransactions, false, false, true },
{ "listunspent", &listunspent, false, false, true }, { "listunspent", &listunspent, false, false, true },
{ "lockunspent", &lockunspent, false, false, true }, { "lockunspent", &lockunspent, true, false, true },
{ "move", &movecmd, false, false, true }, { "move", &movecmd, false, false, true },
{ "sendfrom", &sendfrom, false, false, true }, { "sendfrom", &sendfrom, false, false, true },
{ "sendmany", &sendmany, false, false, true }, { "sendmany", &sendmany, false, false, true },
{ "sendtoaddress", &sendtoaddress, false, false, true }, { "sendtoaddress", &sendtoaddress, false, false, true },
{ "setaccount", &setaccount, true, false, true }, { "setaccount", &setaccount, true, false, true },
{ "settxfee", &settxfee, false, false, true }, { "settxfee", &settxfee, true, false, true },
{ "signmessage", &signmessage, false, false, true }, { "signmessage", &signmessage, true, false, true },
{ "walletlock", &walletlock, true, false, true }, { "walletlock", &walletlock, true, false, true },
{ "walletpassphrasechange", &walletpassphrasechange, false, false, true }, { "walletpassphrasechange", &walletpassphrasechange, true, false, true },
{ "walletpassphrase", &walletpassphrase, true, false, true }, { "walletpassphrase", &walletpassphrase, true, false, true },
/* Wallet-enabled mining */ /* Wallet-enabled mining */