Page MenuHomePhorge
Feed Advanced Search

Yesterday

valerio.bozzolan added a member for Trusted Contributors: banaanihillo.
Wed, Apr 24, 18:47

Tue, Apr 23

20after4 added a member for Trusted Contributors: Iniquity.
Tue, Apr 23, 21:23

Thu, Apr 18

valerio.bozzolan added a member for Trusted Contributors: Mormegil.
Thu, Apr 18, 14:40

Tue, Apr 2

avivey added a member for Trusted Contributors: kat.
Tue, Apr 2, 18:33

Mar 25 2024

valerio.bozzolan added a member for Trusted Contributors: zhe.
Mar 25 2024, 08:51

Mar 12 2024

valerio.bozzolan added a member for Trusted Contributors: tsc.
Mar 12 2024, 10:37

Mar 6 2024

valerio.bozzolan added a member for Trusted Contributors: Krinkle.
Mar 6 2024, 02:17

Feb 7 2024

valerio.bozzolan added a member for Trusted Contributors: revi.
Feb 7 2024, 08:34
valerio.bozzolan added a member for Trusted Contributors: Lectrician1.
Feb 7 2024, 08:29

Feb 5 2024

valerio.bozzolan added a member for Trusted Contributors: philj0st.
Feb 5 2024, 16:47

Feb 4 2024

valerio.bozzolan added a member for Trusted Contributors: pawka.
Feb 4 2024, 09:38

Jan 25 2024

valerio.bozzolan added a member for Trusted Contributors: CryingWolf.
Jan 25 2024, 13:20
valerio.bozzolan added a member for Trusted Contributors: Tgr.
Jan 25 2024, 09:04

Jan 22 2024

valerio.bozzolan added a member for Trusted Contributors: eode.
Jan 22 2024, 21:54

Jan 12 2024

valerio.bozzolan added a member for Trusted Contributors: Harej.
Jan 12 2024, 21:06
valerio.bozzolan added a member for Trusted Contributors: sirocyl.
Jan 12 2024, 08:18

Jan 11 2024

valerio.bozzolan added a member for Trusted Contributors: doommius.
Jan 11 2024, 16:51

Dec 27 2023

valerio.bozzolan added a member for Trusted Contributors: antonia.
Dec 27 2023, 14:56

Dec 10 2023

avivey added a member for Trusted Contributors: adrelanos.
Dec 10 2023, 14:46

Dec 5 2023

avivey added a member for Trusted Contributors: kuba-orlik.
Dec 5 2023, 21:42

Nov 27 2023

Matthew added a member for Trusted Contributors: jeanguyomarch.
Nov 27 2023, 17:03

Nov 5 2023

valerio.bozzolan added a member for Trusted Contributors: l2dy.
Nov 5 2023, 13:38

Oct 3 2023

valerio.bozzolan added a member for Trusted Contributors: fgaz.
Oct 3 2023, 12:56

Aug 31 2023

avivey edited Description on Trusted Contributors.
Aug 31 2023, 11:45
avivey added a member for Trusted Contributors: alufers2.
Aug 31 2023, 11:45

Aug 25 2023

avivey added a member for Trusted Contributors: Juest.
Aug 25 2023, 17:58

Aug 18 2023

valerio.bozzolan added a member for Trusted Contributors: waldyrious.
Aug 18 2023, 07:32

Aug 7 2023

valerio.bozzolan added a member for Trusted Contributors: bob.
Aug 7 2023, 18:42

Jul 24 2023

avivey added a member for Trusted Contributors: kwisatz.
Jul 24 2023, 11:52

Jul 20 2023

avivey added a member for Trusted Contributors: avivey-test-acct.
Jul 20 2023, 17:11

Jul 15 2023

avivey added members for Trusted Contributors: motla, arcadien.
Jul 15 2023, 07:44

Jul 11 2023

avivey added a member for Trusted Contributors: mainframe98.
Jul 11 2023, 10:49

Jul 6 2023

avivey added a member for Trusted Contributors: TitanNano.
Jul 6 2023, 07:13

Jun 30 2023

valerio.bozzolan added a member for Trusted Contributors: szotsaki.
Jun 30 2023, 15:13

Jun 28 2023

Cigaryno edited Description on Trusted Contributors.
Jun 28 2023, 21:26

Jun 22 2023

valerio.bozzolan added a member for Trusted Contributors: jbo.
Jun 22 2023, 15:56

Jun 20 2023

valerio.bozzolan added a member for Trusted Contributors: matmarex.
Jun 20 2023, 06:51

Jun 16 2023

valerio.bozzolan added a member for Trusted Contributors: Sten.
Jun 16 2023, 18:19

Jun 12 2023

taavi added a member for Trusted Contributors: Quartz.
Jun 12 2023, 06:05

May 29 2023

valerio.bozzolan added a member for Trusted Contributors: mturdus.
May 29 2023, 10:18

May 27 2023

valerio.bozzolan added a member for Trusted Contributors: Edward.
May 27 2023, 19:52
valerio.bozzolan added a member for Trusted Contributors: bekay.
May 27 2023, 19:22

May 23 2023

valerio.bozzolan added a member for Trusted Contributors: jkimbo.
May 23 2023, 08:51

May 22 2023

valerio.bozzolan added a member for Trusted Contributors: smith.
May 22 2023, 12:36

May 20 2023

valerio.bozzolan added a member for Trusted Contributors: albertoleoncio.
May 20 2023, 14:22
valerio.bozzolan added a member for Trusted Contributors: jgleeson.
May 20 2023, 12:47

May 12 2023

valerio.bozzolan added a member for Trusted Contributors: arnold.
May 12 2023, 16:01

May 4 2023

valerio.bozzolan added a member for Trusted Contributors: bfs.
May 4 2023, 10:08

May 2 2023

valerio.bozzolan added a member for Trusted Contributors: chrisnovakovic.
May 2 2023, 20:51

Apr 28 2023

valerio.bozzolan added a member for Trusted Contributors: amit.
Apr 28 2023, 10:06

Apr 24 2023

valerio.bozzolan added a member for Trusted Contributors: tinloaf.
Apr 24 2023, 21:50

Apr 20 2023

valerio.bozzolan added a member for Trusted Contributors: MCPCN.
Apr 20 2023, 19:11

Apr 18 2023

valerio.bozzolan added a member for Trusted Contributors: goddenrich.
Apr 18 2023, 14:59

Apr 13 2023

valerio.bozzolan added a member for Trusted Contributors: ton.
Apr 13 2023, 10:29

Apr 12 2023

Cigaryno added a member for Trusted Contributors: Bukkit.
Apr 12 2023, 16:14

Apr 7 2023

avivey edited Description on Trusted Contributors.
Apr 7 2023, 07:39
Cigaryno edited Description on Trusted Contributors.
Apr 7 2023, 07:27
avivey edited Description on Trusted Contributors.
Apr 7 2023, 07:20
Cigaryno edited Description on Trusted Contributors.
Apr 7 2023, 07:18

Apr 5 2023

Cigaryno added a member for Trusted Contributors: aklapper.
Apr 5 2023, 15:54
avivey edited Description on Trusted Contributors.
Apr 5 2023, 07:58

Mar 31 2023

Cigaryno edited Description on Trusted Contributors.
Mar 31 2023, 10:04
valerio.bozzolan added a member for Trusted Contributors: dadalha.
Mar 31 2023, 08:21

Mar 20 2023

Cigaryno added a member for Trusted Contributors: MBinder_WMF.
Mar 20 2023, 17:53
Cigaryno edited Description on Trusted Contributors.
Mar 20 2023, 17:52

Feb 10 2023

MacFan4000 added a member for Trusted Contributors: Dzahn.
Feb 10 2023, 21:32

Jan 7 2023

Cigaryno edited Description on Trusted Contributors.
Jan 7 2023, 08:37
Cigaryno edited Description on Trusted Contributors.
Jan 7 2023, 08:34

Jan 2 2023

Matthew added members for Trusted Contributors: dbcrwk, shimms.
Jan 2 2023, 18:05

Nov 28 2022

Dylsss added a member for Trusted Contributors: valerio.bozzolan.
Nov 28 2022, 15:24

Nov 12 2022

Cigaryno edited Description on Trusted Contributors.
Nov 12 2022, 07:57

Nov 8 2022

Matthew added a member for Trusted Contributors: Higgs.
Nov 8 2022, 18:24

Oct 28 2022

avivey added a member for Trusted Contributors: cristian64.
Oct 28 2022, 07:49

Oct 13 2022

Cigaryno added a member for Trusted Contributors: Dylsss.
Oct 13 2022, 16:03

Sep 24 2022

0 added a member for Trusted Contributors: k__nard.
Sep 24 2022, 18:13

Sep 16 2022

Cigaryno added a member for Trusted Contributors: 20after4.
Sep 16 2022, 18:30
Matthew added a member for Trusted Contributors: Cigaryno.
Sep 16 2022, 18:00

Sep 7 2022

20after4 removed a member for Trusted Contributors: 20after4.
Sep 7 2022, 16:48

Aug 31 2022

avivey closed T15094: Catch up the master branch to upstream as Resolved.

I've cowboy-merged this last week. Not sure why all these commits decided they are part of this task though?

Aug 31 2022, 19:39 · Trusted Contributors, Phorge

Aug 30 2022

Cigaryno added a watcher for Trusted Contributors: Cigaryno.
Aug 30 2022, 17:54

Aug 26 2022

luca.itro added a member for Trusted Contributors: roberto.urbani.
Aug 26 2022, 08:49

May 28 2022

golyalpha added a comment to T15094: Catch up the master branch to upstream.

To be fair, I wouldn't discount already needing access as a viable attack vector, even on private installations.

May 28 2022, 06:38 · Trusted Contributors, Phorge
dcog added a comment to T15094: Catch up the master branch to upstream.

It sounds specific to people who already have access, thank you -- do very much need to pull in latest

May 28 2022, 06:32 · Trusted Contributors, Phorge
golyalpha added a comment to T15094: Catch up the master branch to upstream.

The disclosed issue is that someone can gain access to Files objects they don't have access to by, for example, getting someone with permissions to edit a task they wrote (by including a reference to that file which gets "activated" when the person with permissions to view it saves the edit), which makes the file accessible via the task description.

May 28 2022, 06:19 · Trusted Contributors, Phorge
dcog added a comment to T15094: Catch up the master branch to upstream.

Thanks -- Offhand do you know if this is related to login in that a malicious actor can gain access to source code when unpatched?

May 28 2022, 06:11 · Trusted Contributors, Phorge
golyalpha added a comment to T15094: Catch up the master branch to upstream.

Upstream-T13683

IMPORTANT: This release mitigates a severe security issue which allows attackers with few permission to gain access to files they can not otherwise see. All installs are strongly advised to upgrade.
May 28 2022, 05:10 · Trusted Contributors, Phorge
roguelazer added a comment to T15094: Catch up the master branch to upstream.

FYI today's release (2022 week 21 stable) has a some pretty serious security content

May 28 2022, 00:12 · Trusted Contributors, Phorge

May 21 2022

speck added a comment to T15094: Catch up the master branch to upstream.

@dcog I think the differences with the Harbormaster changes are due to the different approach taken. We planned to do the approach which you took in D25036 which re-played the Phorge diffs on top of phabricator, however in D25040 I just did a merge of the phab/master branch into phorge/master where the Harbormaster changes already existed. Since upstream didn't modify the same Harbormaster files there were no conflicts and things merged appropriately. I did a sanity check of files changed on D25005 with the files changed on D25040.

May 21 2022, 17:06 · Trusted Contributors, Phorge
speck added a comment to T15094: Catch up the master branch to upstream.

Do we even have servers to run the tests on?

May 21 2022, 16:56 · Trusted Contributors, Phorge
speck added a revision to T15094: Catch up the master branch to upstream: D25039: merge phab/master -> phorge/master.
May 21 2022, 16:43 · Trusted Contributors, Phorge
speck added a revision to T15094: Catch up the master branch to upstream: D25040: merge phab/master -> phorge/master.
May 21 2022, 16:43 · Trusted Contributors, Phorge
golyalpha added a comment to T15094: Catch up the master branch to upstream.
In T15094#2292, @speck wrote:

I did not think we had Harbormaster set up to run unit tests - I think that involves configuring both Harbormaster and Drydock, and possibly Almanac which I don't think anyone has done.

I'll go back and review those Harbormaster file changes. Thanks for pointing that out!

May 21 2022, 16:40 · Trusted Contributors, Phorge
golyalpha added a comment to T15094: Catch up the master branch to upstream.
In T15094#2281, @dcog wrote:

This would be a legitimately good exercise to try and do "properly"... although, the thought of not doing it optimally can be a bit of a barrier to starting..

Given the edge cases outlined in T15094#2279, would there be cases in step 2 (or 1?) from T15094#2259 that might benefit from Git cherry-picking? @golyalpha, any thoughts on that? I nearly never have to use cherry-picking, or maybe I should, but either way I'm not very familiar with it other than I'm wondering if it may be relevant

After some reading I'm finding that, as far as I can tell, it's not designed to pick/integrate *specific lines* from a diff, but rather a specific whole commit (from any local or remote branch most likely).. if I'm understanding it correctly

But, perhaps, it could still have the same effect as removing lines from one, and keeping lines from the other when grabbing specific whole commits

The more I think about this the more I'm confusing myself, but hopefully some fraction of this makes sense

May 21 2022, 16:37 · Trusted Contributors, Phorge
speck added a comment to T15094: Catch up the master branch to upstream.

I did not think we had Harbormaster set up to run unit tests - I think that involves configuring both Harbormaster and Drydock, and possibly Almanac which I don't think anyone has done.

May 21 2022, 16:24 · Trusted Contributors, Phorge
dcog added a comment to T15094: Catch up the master branch to upstream.

I would think that your method produced the results we want... though I was noticing this:

May 21 2022, 15:34 · Trusted Contributors, Phorge
dcog added a comment to T15094: Catch up the master branch to upstream.

I see it looks Harbormaster itself does the testing?

May 21 2022, 15:21 · Trusted Contributors, Phorge
dcog added a comment to T15094: Catch up the master branch to upstream.

My vote is that if tests pass we go ahead and do the thing.... More changes in upstream seems fine, and moving forward if we keep up it should get easier and easier hopefully

May 21 2022, 15:18 · Trusted Contributors, Phorge
dcog added a comment to T15094: Catch up the master branch to upstream.

Oh nice!!

May 21 2022, 15:17 · Trusted Contributors, Phorge
dcog added a comment to T15094: Catch up the master branch to upstream.
May 21 2022, 15:15 · Trusted Contributors, Phorge
speck added a comment to T15094: Catch up the master branch to upstream.

Though it does appear additional work has been landing upstream today

May 21 2022, 00:52 · Trusted Contributors, Phorge