Page MenuHomePhorge
Feed All Stories

Apr 19 2022

chris merged task T15093: 502 Bad Gateway error when attempting to view repo info into T15090: CVE-2022-24765 - Multi-user Git Privilege Escalation.
Apr 19 2022, 22:32 · Upstream General/Unknown
chris added a comment to T15093: 502 Bad Gateway error when attempting to view repo info.

This is a direct result of T15090: CVE-2022-24765 - Multi-user Git Privilege Escalation - confirmed in the Nginx error logs:

STDERR
fatal: unsafe repository ('/var/repo/1' is owned by someone else)
To add an exception for this directory, call:
Apr 19 2022, 22:32 · Upstream General/Unknown
dcog added a comment to April 19, 2022.

As I started to thinking about the script to process the pht() files, it hit me that converting something something like:

Apr 19 2022, 21:58 · Governance
dcog added a comment to April 19, 2022.

FYI, it seemed that the issue with the wiki preview loading may be been related to tagging names... if the tags are removed, the preview loads

Apr 19 2022, 21:43 · Governance
Matthew added a project to T15092: Automatic deploy onto we.phorge.it: Upstream General/Unknown.
Apr 19 2022, 21:35 · Phorge.it Systems
dtf added a comment to May 3, 2022.

Nice one, thanks @Matthew!

Apr 19 2022, 21:27
dtf edited the content of May 3, 2022.
Apr 19 2022, 21:26
dtf added a comment to T15093: 502 Bad Gateway error when attempting to view repo info.

Hmm, possibly depending on how it's hosted? What I saw when that CVE was announced on a local instance and on secure. was like the below screenshot, where the repo page was still visible but file structure and recent commits were b0rked:

Apr 19 2022, 21:23 · Upstream General/Unknown
Matthew added a member for Trusted Contributors: luca.itro.
Apr 19 2022, 21:03
Matthew edited projects for T15093: 502 Bad Gateway error when attempting to view repo info, added: Upstream General/Unknown; removed Diffusion (archived).

Related to T15090: CVE-2022-24765 - Multi-user Git Privilege Escalation perhaps? Revisions are stored in the database that's why they're viewable, but the main repository page requires a call to git.

Apr 19 2022, 21:00 · Upstream General/Unknown
Matthew added a comment to May 3, 2022.

@dtf I've added you to the Trusted Contributors project, so you should be able to edit the page now.

Apr 19 2022, 20:58
Matthew added a member for Trusted Contributors: dtf.
Apr 19 2022, 20:57
dtf added a comment to May 3, 2022.

(I am unable to edit the document directly, would someone with the right permissions mind adding this to the agenda please?)

Apr 19 2022, 20:30
dtf added a project to T15093: 502 Bad Gateway error when attempting to view repo info: Diffusion (archived).
Apr 19 2022, 20:08 · Upstream General/Unknown
dtf created T15093: 502 Bad Gateway error when attempting to view repo info.
Apr 19 2022, 20:07 · Upstream General/Unknown
Matthew created an object: May 3, 2022.
Apr 19 2022, 20:04
Matthew edited the content of Planning Meetings.
Apr 19 2022, 20:03 · phorge.it install
Matthew edited the content of April 19, 2022.
Apr 19 2022, 20:02 · Governance
dtf updated dtf.
Apr 19 2022, 19:39
speck updated the task description for T15092: Automatic deploy onto we.phorge.it.
Apr 19 2022, 19:31 · Phorge.it Systems
speck created T15092: Automatic deploy onto we.phorge.it.
Apr 19 2022, 19:29 · Phorge.it Systems
Matthew edited the content of April 19, 2022.
Apr 19 2022, 19:04 · Governance
javier updated the question details for Q11: upgrade phabricator to phorge.
Apr 19 2022, 13:56
javier updated Q11: upgrade phabricator to phorge from upgrade phabricator to forge to upgrade phabricator to phorge.
Apr 19 2022, 10:40
javier asked Q11: upgrade phabricator to phorge.
Apr 19 2022, 10:40

Apr 18 2022

avivey added a comment to T15090: CVE-2022-24765 - Multi-user Git Privilege Escalation.
Apr 18 2022, 19:00 · Security
avivey added a comment to T15091: Possible to find whether an email is attached to an account.

That's intentional (upstream) because it's very hard to make any actual attack with this information can't be made without it.

Apr 18 2022, 18:45 · People, Security

Apr 17 2022

RhinosF1 added a comment to T15091: Possible to find whether an email is attached to an account.

Note: reporter exploited without permission

Apr 17 2022, 07:19 · People, Security
RhinosF1 added projects to T15091: Possible to find whether an email is attached to an account: Security, People (archived).
Apr 17 2022, 07:11 · People, Security
RhinosF1 created T15091: Possible to find whether an email is attached to an account.
Apr 17 2022, 07:11 · People, Security

Apr 16 2022

golyalpha added a comment to T15090: CVE-2022-24765 - Multi-user Git Privilege Escalation.

apparently, Ubuntu maintainers have backported a patch for the older version of git in 20.04 LTS, downgrading to version 1:2.25.1-1ubuntu3 seems to be a temporary workaround, losing the following patches:

I don't think having people downgrade is a good idea. I think we should probably cherry-pick Evan's fix from upstream into the phorge codebase.

Apr 16 2022, 04:58 · Security

Apr 15 2022

Matthew added a comment to T15090: CVE-2022-24765 - Multi-user Git Privilege Escalation.

apparently, Ubuntu maintainers have backported a patch for the older version of git in 20.04 LTS, downgrading to version 1:2.25.1-1ubuntu3 seems to be a temporary workaround, losing the following patches:

Apr 15 2022, 23:40 · Security
golyalpha added a comment to T15090: CVE-2022-24765 - Multi-user Git Privilege Escalation.

ahh, I was wondering why my Phorge install suddenly broke - seems to be the case here too

Apr 15 2022, 19:38 · Security

Apr 14 2022

Matthew added a project to T15090: CVE-2022-24765 - Multi-user Git Privilege Escalation: Phorge General/Unknown.

We need to cherry-pick and import the changes Evan made into the Phorge repository as well...

Apr 14 2022, 13:45 · Security
toilet_bowl_singapore updated toilet_bowl_singapore.
Apr 14 2022, 05:03

Apr 13 2022

avivey shifted T15090: CVE-2022-24765 - Multi-user Git Privilege Escalation from the Restricted Space space to the S1 Public space.
Apr 13 2022, 18:10 · Security
avivey changed the visibility for T15090: CVE-2022-24765 - Multi-user Git Privilege Escalation.
Apr 13 2022, 18:10 · Security
avivey added a comment to T15090: CVE-2022-24765 - Multi-user Git Privilege Escalation.

err, I was trying to put it out as a Security PSA, so I clicked "Create security task" which I guess is the opposite of a PSA...

Apr 13 2022, 18:09 · Security
avivey created T15090: CVE-2022-24765 - Multi-user Git Privilege Escalation.
Apr 13 2022, 18:07 · Security

Apr 11 2022

20after4 added a comment to T15084: Discussion: Maniphest vs Ponder for user support.

I'm setting the "Moderate" policy on Ponder to Trusted Contributors and I'll add a link to Ponder from the default home page.

Apr 11 2022, 17:17 · phorge.it install
20after4 changed the Moderate Policy policy for application Ponder from Administrators to Trusted Contributors (Project).
Apr 11 2022, 17:16
20after4 awarded T15084: Discussion: Maniphest vs Ponder for user support a Mountain of Wealth token.
Apr 11 2022, 17:15 · phorge.it install

Apr 9 2022

dcog added a comment to April 5, 2022.

Some initial findings on Rector...

Apr 9 2022, 19:43 · Governance

Apr 6 2022

20after4 awarded April 5, 2022 a Mountain of Wealth token.
Apr 6 2022, 16:59 · Governance

Apr 5 2022

Matthew created an object: April 19, 2022.
Apr 5 2022, 20:00 · Governance
Matthew edited the content of Planning Meetings.
Apr 5 2022, 19:58 · phorge.it install
Matthew added a comment to T15012: Update Diviner documentation to reference Phorge.

As discussed in {E2}, we might add temporary banners to Diviner to state that we are rebranding. This would allow some time for us to handle the code rebrand and address the underlying Diviner issues before we edit everything twice.

Apr 5 2022, 19:56 · Phorge
Matthew assigned T15084: Discussion: Maniphest vs Ponder for user support to 20after4.

As discussed in {E2}, we will be implementing this to control spam for now. If this doesn't work, we will revisit this discussion.

Apr 5 2022, 19:53 · phorge.it install
Matthew edited the content of April 5, 2022.
Apr 5 2022, 19:52 · Governance
avivey changed the join policy for Trusted Contributors.
Apr 5 2022, 19:45
Matthew triaged T15088: Allow for Diviner books to live in their own Repo as Wishlist priority.
Apr 5 2022, 19:00 · Diviner
Matthew added a comment to T15012: Update Diviner documentation to reference Phorge.

I will note that also the tech docs aren’t fully generated since there should be docs for most of the phorge/phabricator classes. Also the arcanist docs aren’t generated at all.

Apr 5 2022, 18:57 · Phorge
Matthew created an object: April 5, 2022.
Apr 5 2022, 18:46 · Governance
Matthew edited the content of Planning Meetings.
Apr 5 2022, 18:41 · phorge.it install

Apr 4 2022

Matthew renamed T15087: [removed] from Can Cash App Be Hacked If You Are A New User Who Is Using The Low Security Feature? to [removed].
Apr 4 2022, 18:11
golyalpha added a comment to T15059: Phabricator doesn't email @outlook.com addresses.

Alright, I've just went through a similar process - they apparently have changed their process a little but there still is a form to fill out: https://support.microsoft.com/en-us/getsupport?oaspworkflow=start_1.0.0.0&wfname=capsub&productkey=edfsmsbl3 (you need a Microsoft Account to fill it out, but they'll contact you on the contact email you give in the form)

Apr 4 2022, 10:06 · phorge.it install
golyalpha closed T15087: [removed] as Invalid.

Obviously spam.

Apr 4 2022, 09:58
miler7425 created T15087: [removed].
Apr 4 2022, 06:21

Apr 3 2022

golyalpha created T15086: Support Inbound Mail over IMAP.
Apr 3 2022, 18:17 · Mail

Apr 2 2022

alinaparker186 updated alinaparker186.
Apr 2 2022, 13:00
canvas_supplier_singapore updated canvas_supplier_singapore.
Apr 2 2022, 10:41

Apr 1 2022

golyalpha added a comment to T15082: Consider allowing milestone columns to be ordered arbitrarily on workboards.

Reordering milestones is convenient when you want to treat milestones as workflow steps rather than sequential numerical versions.

Apr 1 2022, 05:40 · Discussion Needed, Affects-Wikimedia, Workboard

Mar 31 2022

20after4 added a comment to T15082: Consider allowing milestone columns to be ordered arbitrarily on workboards.

epriestley was very much against this idea but wikimedia's users loved it.

Do we have epristley's reasoning as to why he was against this? Might help in deciding about including this patch in Phorge.

Mar 31 2022, 23:55 · Discussion Needed, Affects-Wikimedia, Workboard
bird_control updated bird_control.
Mar 31 2022, 09:27

Mar 30 2022

Matthew closed D25035: Hide the blurb of a user when that user is disabled.
Mar 30 2022, 15:17
Matthew committed rP7d4357683a31: Hide the blurb of a user when that user is disabled.
Hide the blurb of a user when that user is disabled
Mar 30 2022, 15:17
Matthew renamed T15085: [removed] from Can Cash App Be Hacked If Someone Compromise The Password? to [removed].
Mar 30 2022, 15:10
Matthew closed T15085: [removed] as Spite.
Mar 30 2022, 15:10
dinhickup updated dinhickup.
Mar 30 2022, 06:09
dinhickup created T15085: [removed].
Mar 30 2022, 06:07
mrbk25 updated mrbk25.
Mar 30 2022, 04:43
mrbk25 updated mrbk25.
Mar 30 2022, 04:43
mrbk25 updated mrbk25.
Mar 30 2022, 04:42
mrbk25 updated mrbk25.
Mar 30 2022, 04:42

Mar 29 2022

Matthew triaged T15084: Discussion: Maniphest vs Ponder for user support as Low priority.
Mar 29 2022, 16:25 · phorge.it install
golyalpha added a comment to T15077: Rebrand: Tracking task.

Since all changes are going to be submitted to the upstream prior to landing here in Phorge it would be easiest if changes were made to a clone of Phabricator and not a clone of Phorge.

Mar 29 2022, 07:26 · Phorge
golyalpha added a comment to T15082: Consider allowing milestone columns to be ordered arbitrarily on workboards.

epriestley was very much against this idea but wikimedia's users loved it.

Mar 29 2022, 07:16 · Discussion Needed, Affects-Wikimedia, Workboard
woakeschris41 updated woakeschris41.
Mar 29 2022, 06:31
Matthew added a comment to T15075: Add support for @link in diviner.

Thanks for your comments! Namespacing might be useful, we would have to figure out what that looked like. I was thinking "/book/group/link" as that would be pretty natural (and is very close to what Diviner does already: "/book/group/filename"). It would also allow for us to eventually make Diviner widely useful, see secure: T4558. However, that is a broader discussion that should probably wait...

Mar 29 2022, 03:54 · Diviner, Remarkup
speck added a comment to T15075: Add support for @link in diviner.

A few thoughts. This sounds like a great idea as searching by article title seems a little fragile as you mention. I think a good practice for using the proposed @link would be to fully namespace it somehow like @link development.processes.i18n, though I'm not totally sure what that looks like as I'm not familiar with the Diviner format or structure. If we have the use of namespaces then managing multiple @link declarations might lead to confusion or tedious to maintain. To me this also feels more similar to something like an @id rather than @link. What are your thoughts?

Mar 29 2022, 03:36 · Diviner, Remarkup
speck added a comment to T15079: Upstream translatewiki.net's changes.

A highly unfortunate side-effect of T15077: Rebrand: Tracking task is that it will invalidate a ton of translations. My guess is that upstream did not want to maintain these translations as part of the release product, possibly due to not requiring translations be part of the Phabricator release process. If we pull them into the Phorge codebase then we would likely need to update all translations for any text changes made during development, prior to release. I think it would make sense to host the translations in a repository here but I would worry about them quickly falling out of date. Handling of translations is likely a larger-sized project that we would need help managing.

Mar 29 2022, 03:30 · Localization
speck edited the content of March 21, 2022.
Mar 29 2022, 03:18
speck added a comment to T15006: Re-brand Phorge.

As part of {E1} we reviewed this as a priority item, and have created T15077: Rebrand: Tracking task for concrete first steps forwards. There is a lot of text to update and review and that task is setup with instructions on how we're approaching it as well as listing out all the individual applications to update. Anyone interested in assisting please review that task and feel free to put your name on an application/folder, as well as ask any questions for clarification.

Mar 29 2022, 03:17 · Phorge
speck edited the content of March 21, 2022.
Mar 29 2022, 03:13
speck updated the task description for T15077: Rebrand: Tracking task.
Mar 29 2022, 03:13 · Phorge
speck added a comment to T15077: Rebrand: Tracking task.

I put up some coding guidelines that I could recall from when I was working with upstream on example changes. I won't be back at my home office for another week so there may be some things I'm missing but I think a number of things were covered/discussed with Evan on the example changes in https://secure.phabricator.com/D21712.

Mar 29 2022, 03:08 · Phorge
Matthew closed T15071: Setup recurring Core meeting as Resolved.

I am closing this, future meetings are scheduled now. See March 21, 2022 for more information.

Mar 29 2022, 03:04 · Governance
speck updated the task description for T15077: Rebrand: Tracking task.
Mar 29 2022, 03:00 · Phorge
Matthew created T15083: Lipsum randomly fails when there are no repositories defined.
Mar 29 2022, 02:59
speck edited the content of Planning Meetings.
Mar 29 2022, 02:41 · phorge.it install
speck updated the task description for T15077: Rebrand: Tracking task.
Mar 29 2022, 02:35 · Phorge
speck updated the task description for T15077: Rebrand: Tracking task.
Mar 29 2022, 02:35 · Phorge
speck created an object: March 21, 2022.
Mar 29 2022, 02:34
speck edited the content of Planning Meetings.
Mar 29 2022, 02:29 · phorge.it install
speck created an object: Planning Meetings.
Mar 29 2022, 02:25 · phorge.it install
Matthew updated the task description for T15077: Rebrand: Tracking task.
Mar 29 2022, 00:42 · Phorge

Mar 25 2022

20after4 added a subtask for T15081: Figure out if there are patches from Wikimedia's fork that are desirable to upstream in Phorge: T15082: Consider allowing milestone columns to be ordered arbitrarily on workboards.
Mar 25 2022, 13:18 · Discussion Needed, Affects-Wikimedia
20after4 added a parent task for T15082: Consider allowing milestone columns to be ordered arbitrarily on workboards: T15081: Figure out if there are patches from Wikimedia's fork that are desirable to upstream in Phorge.
Mar 25 2022, 13:18 · Discussion Needed, Affects-Wikimedia, Workboard
20after4 added a project to T15082: Consider allowing milestone columns to be ordered arbitrarily on workboards: Projects (archived).
Mar 25 2022, 13:17 · Discussion Needed, Affects-Wikimedia, Workboard
20after4 created T15082: Consider allowing milestone columns to be ordered arbitrarily on workboards.
Mar 25 2022, 13:17 · Discussion Needed, Affects-Wikimedia, Workboard