• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

IJHack / QtPass / 35638958349
93%

Build:
DEFAULT BRANCH: main
Ran 21 Sep 2026 06:39PM UTC
Jobs 1
Files 114
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

21 Sep 2026 06:31PM UTC coverage: 78.994% (-0.02%) from 79.01%
35638958349

push

github

web-flow
Copy: the object read is the object judged (#1883)

* Copy: the object read is the object judged

ImitatePass::Copy() judged the source with refuseLinkedPath() and then
copyFileReplacing() opened it by name, through whatever link a co-writer
of the store had put under the name in between: the bytes of any file this
user can read, copied into the store as an entry and committed before the
re-encryption could notice they were no ciphertext.

Util::openRegularFile() opens without following (O_NOFOLLOW and fstat on
POSIX; FILE_FLAG_OPEN_REPARSE_POINT and the handle's attributes on
Windows) and accepts a regular file only: a link, a directory, a FIFO (the
open does not block on it) or a device under the name fails. The copy is
written to a temporary next to the destination through its open handle
and given the destination's name with Util::replaceFile(), as an added
entry is since the previous change; QSaveFile, which resolved a link
under the destination name at open, is not used for entries any more.
Without force nothing under the name is replaced, also nothing that
appeared since the check.

Tests: tst_util pins openRegularFile (regular file read, missing file,
directory, link although a plain QFile reads through it, FIFO; a junction
on Windows); tst_imitatepass pins the copy's bytes and staging, no
temporary left, an unforced copy keeping an existing entry and a forced
one replacing it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuQsrHonihp1nARE7bzstc

* tst_imitatepass: the copy test uses a shell fake gpg; skip it on Windows

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuQsrHonihp1nARE7bzstc

* Util::openRegularFile: tell CodeQL the descriptor is what is opened

Its check-then-use matcher flags QFile::open(fd) after fstat(fd) as a
race on the name; the name is not opened again, the descriptor is.

Co-Authored-By: Claude Opus 5 <nore... (continued)

21 of 28 new or added lines in 2 files covered. (75.0%)

7431 of 9407 relevant lines covered (78.99%)

80.52 hits per line

Uncovered Changes

Lines Coverage ∆ File
5
76.18
-0.18% src/imitatepass.cpp
2
89.53
-0.53% src/util.cpp
Jobs
ID Job ID Ran Files Coverage
1 35638958349.1 21 Sep 2026 06:39PM UTC 114
78.99
GitHub Action Run
Source Files on build 35638958349
  • Tree
  • List 114
  • Changed 2
  • Source Changed 2
  • Coverage Changed 2
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35638958349
  • adcf2a7c on github
  • Prev Build on main (#35635087026)
  • Next Build on main (#35646452898)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc