• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

IJHack / QtPass / 35457665089
93%

Build:
DEFAULT BRANCH: main
Ran 19 Sep 2026 05:26PM UTC
Jobs 1
Files 113
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

19 Sep 2026 05:18PM UTC coverage: 77.427% (+0.01%) from 77.417%
35457665089

push

github

web-flow
Verify the .gpg-id bytes that are used, commit list and signature together (#1843)

* Verify the .gpg-id bytes that are used, commit list and signature together

Three related holes in the signed-recipients model, all from reading the
file more than once:

The signature was checked on the path and the recipients were then read
from the file again, in Insert() and in the re-encryption loop. Anyone
who can write to the store in that window chooses the recipients. gpg now
verifies the bytes on stdin (`--verify <sig> -`), Pass::parseRecipients
parses those same bytes, and the re-encryption cache maps each .gpg-id to
the recipient list its verified contents held.

The .gpg-id and its signature went into two commits, so the history had a
state with the new list under the old signature, permanently when the
second commit failed; and Init() started re-encrypting even when the
commit had failed, leaving the working tree on a list the repository did
not have. One add and one commit for both files now, nothing committed
when nothing changed, and a failed commit ends Init with processErrorExit
before any entry is touched.

A failed automatic pull before re-encryption aborts the run when it left
unmerged files; a pull that only failed to reach the remote continues as
before. The profile form requires full fingerprints as signing key, since
that is what pass compares with gpg's VALIDSIG.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuQsrHonihp1nARE7bzstc

* Wrap a comment clang-format did not like

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuQsrHonihp1nARE7bzstc

* Write .gpg-id atomically and stop when it fails; diff exit codes; wording

writeGpgIdFile ignored write errors and Init went on to sign and
re-encrypt whatever landed on disk, so a full disk turned the chosen
recipients into a truncated, correctly signed list. QSaveFile now, the
result ... (continued)

103 of 123 new or added lines in 4 files covered. (83.74%)

6 existing lines in 1 file now uncovered.

6692 of 8643 relevant lines covered (77.43%)

73.95 hits per line

Uncovered Changes

Lines Coverage ∆ File
19
75.31
-0.45% src/imitatepass.cpp
1
95.45
-0.97% src/gpgidsigner.cpp

Coverage Regressions

Lines Coverage ∆ File
6
75.31
-0.45% src/imitatepass.cpp
Jobs
ID Job ID Ran Files Coverage
1 35457665089.1 19 Sep 2026 05:26PM UTC 113
77.43
GitHub Action Run
Source Files on build 35457665089
  • Tree
  • List 113
  • Changed 8
  • Source Changed 8
  • Coverage Changed 5
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35457665089
  • 4f29aaee on github
  • Prev Build on main (#35437047893)
  • Next Build on main (#35459543851)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc