• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

IJHack / QtPass / 34836637500
93%

Build:
DEFAULT BRANCH: main
Ran 14 Sep 2026 11:13AM UTC
Jobs 1
Files 88
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

14 Sep 2026 11:08AM UTC coverage: 68.184% (+0.005%) from 68.179%
34836637500

push

github

web-flow
Backport: Pass --no-encrypt-to on every gpg encrypt call (#1709) (#1725)

* Pass --no-encrypt-to on every gpg encrypt call (#1682)

ImitatePass::Insert() and the per-file re-encryption in
reencryptSingleFile() ran gpg -eq with only the -r recipients from
.gpg-id. gpg still honours an `encrypt-to <key>` line in the user's
gpg.conf on such calls, so a stray or malicious gpg.conf could add a
recipient that the (optionally signed) .gpg-id never listed, and every
file written by QtPass would silently be readable by that key.
--no-encrypt-to was only present on the decrypt calls, where it does
nothing.

Add --compress-algo=none --no-encrypt-to to both encrypt argv, exactly
as pass(1) does through its GPG_OPTS. The flags on the decrypt calls
are left in place; pass applies the same GPG_OPTS to decryption too and
they are harmless there.

Tests: tst_imitatepass drives Insert() and reencryptPath() through a
recording fake gpg and checks the encrypt argv (flags present, the
.gpg-id recipient still the only -r, insert/re-encrypt still succeed).
tst_integration adds `encrypt-to <second key>` to the throwaway
gpg.conf and verifies with gpg --list-packets that Insert and
re-encryption produce files targeting only the .gpg-id key while still
decrypting to the inserted content. All four fail on the unfixed code.

Backport to 1.8 (#1709): the tests/auto/imitatepass suite did not exist
on main (it was introduced by the 2.0-only re-encryption worker, #1697),
so this commit creates it with only the two encrypt-argv tests; the
worker-thread tests were left out and the re-encrypt test waits on the
synchronous reencryptPath() through plain QSignalSpy instead of queued
connections. The suite is registered in tests/auto/auto.pro and its
binary added to .gitignore. src/ and tst_integration changes applied
unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuQsrHonihp1nARE7bzstc
(cherry picked from commit 45317d58e... (continued)

3 of 3 new or added lines in 1 file covered. (100.0%)

5004 of 7339 relevant lines covered (68.18%)

92.5 hits per line

Jobs
ID Job ID Ran Files Coverage
1 34836637500.1 14 Sep 2026 11:13AM UTC 88
68.18
GitHub Action Run
Source Files on build 34836637500
  • Tree
  • List 88
  • Changed 3
  • Source Changed 3
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34836637500
  • ff647c10 on github
  • Prev Build on main (#34835706449)
  • Next Build on main (#34836650519)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc