• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

IJHack / QtPass / 35543022646
93%

Build:
DEFAULT BRANCH: main
Ran 20 Sep 2026 11:00PM UTC
Jobs 1
Files 112
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

20 Sep 2026 10:53PM UTC coverage: 78.338% (+0.2%) from 78.154%
35543022646

push

github

web-flow
A link inside the store is not part of it, at every operation (#1864)

* A link inside the store is not part of it, at every operation

#1848 and #1851 made the walks (re-encryption, search, staging) skip
symbolic links and junctions. The ordinary operations still followed them:
the tree shows a linked entry like any other, and gpg, pass and QFile all
read and write through a link, so a planted Bank.gpg -> /elsewhere/x.gpg
was shown when clicked, and Edit would have re-encrypted whatever it
pointed to with the store's recipients and committed it; a new entry saved
into a linked folder landed outside the store; Copy read the target's
bytes into the store. A shared store's co-writer can make git pull create
such links.

Pass::refuseLinkedPath() is the one rule: an entry or folder that is, or
lies behind, a link inside the store is refused with a message before
anything runs, in both backends, for Show, Insert, Move, Copy and Init.
Remove treats the link itself as removable (git rm, pass rm and
QFile::remove unlink it) and refuses only what lies behind one. The
configured store root may still be a link.

Metadata follows the same rule: getGpgIdPath() does not take a link under
the .gpg-id name for a folder's list (the parent's applies), a linked root
list reads as missing in getRecipientList() and loadVerifiedRecipients(),
and GpgIdSigner refuses a linked .gpg-id or .gpg-id.sig before gpg is
asked, so a validly signed pair cannot be replayed through two links.

SECURITY.md states the rule and the shared-store model it answers.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuQsrHonihp1nARE7bzstc

* Links: the leaf under .gpg-id, the file a drop lands on, pass rm on a linked folder, and the interface

Findings of the adversarial pass over the previous commit, each reproduced
before it was fixed:

- pass's cmd_delete turns a folder into "<folder>/" and rm -rf then follows
  a link and empties its tar... (continued)

93 of 104 new or added lines in 6 files covered. (89.42%)

28 existing lines in 4 files now uncovered.

7012 of 8951 relevant lines covered (78.34%)

76.04 hits per line

Uncovered Changes

Lines Coverage ∆ File
6
89.11
-3.54% src/realpass.cpp
3
76.57
1.69% src/imitatepass.cpp
1
94.59
-0.93% src/gpgidsigner.cpp
1
85.5
0.31% src/pass.cpp

Coverage Regressions

Lines Coverage ∆ File
18
32.47
-0.43% src/moc_mainwindow.cpp
8
0.0
0.0% src/qrc_qmake_qmake_qm_files.cpp
1
76.57
1.69% src/imitatepass.cpp
1
86.42
-1.23% src/nativegrep.cpp
Jobs
ID Job ID Ran Files Coverage
1 35543022646.1 20 Sep 2026 11:00PM UTC 112
78.34
GitHub Action Run
Source Files on build 35543022646
  • Tree
  • List 112
  • Changed 12
  • Source Changed 11
  • Coverage Changed 10
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35543022646
  • 63958f35 on github
  • Prev Build on main (#35473502079)
  • Next Build on main (#35589605901)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc