• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

IJHack / QtPass / 35589605901
93%

Build:
DEFAULT BRANCH: main
Ran 21 Sep 2026 10:42AM UTC
Jobs 1
Files 114
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

21 Sep 2026 10:35AM UTC coverage: 78.866% (+0.5%) from 78.338%
35589605901

push

github

web-flow
Signed .gpg-id: refuse a rollback to an older generation (#1869)

* Signed .gpg-id: refuse a rollback to an older generation

A signature proves that a recipient list is authentic and unmodified, not
that it is the current one. Whoever can write to a shared store can put
back an older, genuinely signed list that still names a member since
removed, and every later Insert and re-encryption would encrypt to them
again. pass has the same property; QtPass inherited the model with the
signing feature.

Every .gpg-id QtPass writes (ImitatePass::writeGpgIdFile,
ProfileInit::writeGpgId, Pass::seedGpgIdFile) now starts with one comment
line, "# QtPass-GpgId-Generation: N", that pass and Pass::parseRecipients
ignore and the signature covers. GpgIdGeneration keeps, per .gpg-id
(keyed by a SHA-256 of its canonical path, in a settings file of its own
with fallbacks off), the highest generation this device has accepted or
written, written through with sync() before it counts. With signing on,
loadVerifiedRecipients() refuses a verified list whose generation is lower
than that, with a message naming both numbers and the way through (save
the recipients again, which writes one above). The parser is strict: no
line is generation 0 (a list from pass or from before), exactly one
well-formed line is its number, a malformed or duplicated line makes the
list unusable rather than 0, so parser ambiguity is not a downgrade.

What it is not, stated in SECURITY.md: freshness for a device that never
saw the newer list (first sight, or offline for the change) is out of
reach without a server; the generation is monotonic per device, two
devices can both produce the same next one and Git resolves that; the pass
backend's pass reads the list itself.

Tests: a new tst_gpgidgeneration suite (grammar, key canonicalisation,
accept/remember/next, write-through), an end-to-end rollback in
tst_imitatepass with the signing fake gpg (generation 1 with Bob,
generation 2 without, the generation... (continued)

202 of 211 new or added lines in 4 files covered. (95.73%)

9 existing lines in 1 file now uncovered.

7221 of 9156 relevant lines covered (78.87%)

75.85 hits per line

Uncovered Changes

Lines Coverage ∆ File
4
97.69
src/gpgidgeneration.cpp
4
77.29
0.72% src/imitatepass.cpp
1
70.34
8.73% src/profileinit.cpp

Coverage Regressions

Lines Coverage ∆ File
9
0.0
0.0% src/qrc_qmake_qmake_qm_files.cpp
Jobs
ID Job ID Ran Files Coverage
1 35589605901.1 21 Sep 2026 10:42AM UTC 114
78.87
GitHub Action Run
Source Files on build 35589605901
  • Tree
  • List 114
  • Changed 9
  • Source Changed 8
  • Coverage Changed 6
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35589605901
  • f76ba170 on github
  • Prev Build on main (#35543022646)
  • Next Build on main (#35590881210)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc