• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

IJHack / QtPass / 35646452898
93%

Build:
DEFAULT BRANCH: main
Ran 21 Sep 2026 07:50PM UTC
Jobs 1
Files 114
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

21 Sep 2026 07:41PM UTC coverage: 79.015% (+0.02%) from 78.994%
35646452898

push

github

web-flow
.gpg-id and its signature: written staged, signed over the bytes written (#1884)

* .gpg-id and its signature: written staged, signed over the bytes written

The recipient list and its signature were the last writes of entries,
lists and signatures that opened a store path by name after the link
check: .gpg-id through QSaveFile, which resolves a link under the name at
open (from the Users dialog, a new profile, and a new folder seeded with
its parent's list), and .gpg-id.sig by gpg --detach-sign in place, with
gpg reading the list back by name to sign it. A co-writer of the store who
swapped the list between the write and the signing would have had the
user's key vouch for theirs.

GpgIdSigner::sign() takes the bytes the caller just wrote and feeds them
to gpg on stdin (UTF-8 text, as verify() requires; anything else is
refused before gpg runs), with --output in a QTemporaryDir of QtPass's
own; the signature then goes next to the list through
Util::writeFileReplacing(): a staged sibling with an opaque name, written
by its open handle, flushed to the device (Util::syncToDisk, what
QSaveFile's commit did), given the name with the operating system's
rename, so a link planted under .gpg-id.sig since the check is replaced as
an entry (on Windows a junction there fails the write instead: MoveFileEx
does not replace a directory). ImitatePass::writeGpgIdFile(),
ProfileInit::writeGpgId() and Pass::seedGpgIdFile() write the list the
same way, the first two handing the bytes on to the signing step; the
Insert and Copy staging flush to the device too.

Tests: tst_gpgidsigner pins the stdin bytes, the --output outside the
store, the signature placed and the scratch gone, a gpg that writes an
empty signature leaving the old one, bytes that are not UTF-8 refused with
gpg not run, and a link under the .sig name replaced with its target
untouched; tst_util pins writeFileReplacing (owner-only, no temporary
left, refused without replace, a link replaced as an entry; on ... (continued)

108 of 140 new or added lines in 5 files covered. (77.14%)

3 existing lines in 2 files now uncovered.

7478 of 9464 relevant lines covered (79.02%)

80.3 hits per line

Uncovered Changes

Lines Coverage ∆ File
15
76.91
0.74% src/imitatepass.cpp
14
85.65
-3.87% src/util.cpp
3
92.31
-2.29% src/gpgidsigner.cpp

Coverage Regressions

Lines Coverage ∆ File
2
76.91
0.74% src/imitatepass.cpp
1
86.42
-1.23% src/nativegrep.cpp
Jobs
ID Job ID Ran Files Coverage
1 35646452898.1 21 Sep 2026 07:50PM UTC 114
79.02
GitHub Action Run
Source Files on build 35646452898
  • Tree
  • List 114
  • Changed 8
  • Source Changed 7
  • Coverage Changed 7
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35646452898
  • ec2c387b on github
  • Prev Build on main (#35638958349)
  • Next Build on main (#35646821641)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc