• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / integrity / 32045366698
91%

Build:
DEFAULT BRANCH: main
Ran 17 Aug 2026 04:26PM UTC
Jobs 1
Files 14
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

17 Aug 2026 04:23PM UTC coverage: 90.056% (+0.007%) from 90.049%
32045366698

push

github

web-flow
fix: validate the CIDR prefix before using it as a shift distance (#60)

ipInCidr() took whatever followed the slash, cast it to int and shifted
by it. Three ways that went wrong, all reachable from an ip_whitelist
an administrator typed:

  0.0.0.0/0     -1 << (32 - 0) shifts by the full width, which is the
                undefined case. On a 64-bit build it yields -4294967296
                rather than 0, so an entry written to mean "allow any
                address" matched nothing and locked the key out.

  10.0.0.0/     the empty prefix cast to 0 and took the same path.

  2001:db8::/200 intdiv(200, 4) = 50 walked past the end of a 32-char
                hex string, and the remainder branch then read an
                uninitialised string offset.

The prefix is now required to be a plain digit string in range for the
family before it is used, and anything else is refused. A whitelist
entry that cannot be parsed must not be read as permission — refusing is
the safe direction here, since the whitelist only ever narrows access.
/0 is answered directly as "every address" rather than by shifting.

The IPv6 branch also compared inet_pton() output without checking the
families matched, so an IPv4 subnet paired with an IPv6 client compared
4 bytes against 16. That is now a non-match rather than a nibble walk
over mismatched lengths.

2590 of 2876 relevant lines covered (90.06%)

3.38 hits per line

Coverage Regressions

Lines Coverage ∆ File
6
95.71
-0.25% integrity/integrity/src/Auth/ApiKeyManager.php
Jobs
ID Job ID Ran Files Coverage
1 32045366698.1 17 Aug 2026 04:26PM UTC 14
90.06
GitHub Action Run
Source Files on build 32045366698
  • Tree
  • List 14
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #32045366698
  • 5c9b1110 on github
  • Prev Build on main (#31332366469)
  • Next Build on main (#32052804035)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc