Mercurial 3.7 (2016-02-01)#

Mercurial 3.7.3 (2016-03-29)#

This is an out of cycle release to address three security issues:

CVE-2016-3630 Mercurial: remote code execution in binary delta decoding

Mercurial prior to 3.7.3 contained two bounds-checking errors in its binary delta decoder that may be exploitable via clone, push, or pull.

CVE-2016-3068 Mercurial: arbitrary code execution with Git subrepos

Mercurial prior to 3.7.3 allowed URLs for Git subrepos that could result in arbitrary code execution on clone. This is a further side-effect of Git CVE-2015-7545. Reported by Blake Burkhart.

CVE-2016-3069 Mercurial: arbitrary code execution when converting Git repos

Mercurial prior to 3.7.3 allowed arbitrary code execution when converting Git repos with hostile names. This could affect automated conversion services. Reported by Blake Burkhart.

  • bdiff: (pure) support array.array arrays (issue5130)

  • convert: add new, non-clowny interface for shelling out to git (SEC)

  • convert: dead code removal - old git calling functions (SEC)

  • convert: rewrite calls to Git to use the new shelling mechanism (SEC)

  • convert: rewrite gitpipe to use common.commandline (SEC)

  • convert: test for shell injection in git calls (SEC)

  • files: don't recurse into subrepos without a path or -S (issue5127)

  • hg: perform update after pulling during clone with share (issue5103)

  • mq: restrict generated patch name to 75 characters (issue5117)

  • obsolete: fix n^2 marker computation behavior

  • parsers: detect short records (SEC)

  • parsers: fix list sizing rounding error (SEC)

  • streamclone: fix error when store files grow while stream cloning

  • subrepo: adapt to git's recent renames-by-default

  • subrepo: set GIT_ALLOW_PROTOCOL to limit git clone protocols (SEC)

Mercurial 3.7.2 (2016-03-01)#

This is a regularly-scheduled bugfix release.

  • bundlerepo: properly handle hidden linkrev in filelog (issue4945)

  • bundlerepo: properly handle hidden linkrev in manifestlog (issue4945)

  • demandimport: add _imp to ignore list

  • doc: correct example concerning "hg purge" alias in man page "hgrc.5"

  • doc: remove deprecated option from synopsis of command help

  • fileset: fix copy/paste in eol() error message

  • help: fix typo in backgroundclose documentation

  • help: hg.intevation.de is new primary name of hg.intevation.de (and new cert)

  • help: update template examples to use reST literal syntax

  • hg: obtain lock when creating share from pooled repo (issue5104)

  • log: fix order of revisions filtered by multiple OR options (issue5100)

  • rebase: update working directory when aborting (issue5084)

  • revert: properly revert to ancestor of p2 during merge (issue5052)

  • revset: flatten chained 'list' operations (aka function args) (issue5072)

  • setup: avoid procedure related to hg.exe at setup.py --pure

  • ui: fix crash by non-interactive prompt echo for user name

  • unionrepo: properly handle hidden linkrev in revlog (issue5070)

  • zeroconf: forward all arguments passed to ui.configitems() wrapper

Mercurial 3.7.1 (2016-02-03)#

This addresses an urgent regression in compilation on Solaris and metadata handling for conversions.

  • amend: don't preserve most extra fields

  • graft: don't preserve most extra fields

  • histedit: fix typo in documentation

  • osutil: disable compilation of recvfds() on unsupported platforms

  • osutil: do not abort loading pure module just because libc has no recvmsg()

  • rebase: backout changeset 986d04b9fedd

  • rebase: backout changeset d755a9531fce

  • rebase: don't preserve most extra fields

Mercurial 3.7 release#

Features#

  • [[GeneralDelta]]: the original Mercurial compression format had an inefficient way of storing history in very branchy repositories. Generaldelta addresses this weakness. As a result, depending on the repository, this can improve the size of the history up to a factor of 10. Mercurial 1.9 was the first release to support generaldelta (behind a feature flag), but Mercurial 3.7 also allows pulling a mixture of non-generaldelta and generaldelta history without having to recompute everything, which avoids overloading servers. As a result, generaldelta is now enabled by default. You can convert a repository to generaldelta using: {{{ hg clone -U --config format.generaldelta=1 --pull originalrepo generaldeltarepo }}}

  • Clonebundles: this is an server-side extension. It allows using a pre-generated bundle for an initial Mercurial clone. Clients will automatically use clonebundles if a server advertises them. Clonebundles allows much faster initial clones and reduces the load on a central server significantly. Mercurial 3.6 was the first version to include experimental clonebundles support, it's now been marked non-experimental. You can find out more using: {{{hg help clonebundles}}}.

  • Filesets now support 'missing()', to specify all files missing according to {{{hg status}}}.

  • Interactive committing ({{{hg commit -i}}}) and amending ({{{hg commit --amend}}}) can now be used together.

  • Merging can now handle collisions between untracked and tracked files, configurable according to the config option {{{merge.checkunknown}}}.

  • Default 'histedit' destination: it's now possible to run {{{hg histedit}}} without specifying a base revision. Mercurial will try to determine an appropriate base automatically. The revset used for this is "{{{reverse(only(.) and not public() and not ::merge())}}}", which specifies the first ancestor of the current changeset that is not public and does not have any descendants that are merges.

  • The '*.orig' files created by revert can now be stored in a different location, specified by the config option {{{ui.origbackuppath}}}.

  • {{{hg shelve}}} now supports storing untracked files.

  • {{{hg unshelve}}} now supports using a custom merge tool.

  • {{{hg backout}}} now commits by default if no conflicts were encountered.

  • hgweb now supports rendering sub-topics.

  • Server operators can now limit interaction with legacy clients speaking an outdated wire protocol. This is useful for preventing excessive CPU use when the server is using generaldelta repositories. See the various {{{bundle1}}} options in {{{hg help config.server}}}.

  • Python wheel packages are now available for Windows on PyPI

  • {{{[paths]}}} entries can now define a separate URL for pushes. See {{{hg help config.paths}}} for more.

Improvements#

This release includes many improvements, including (but not limited to):

  • performance improvements (speedup for 'hg log <file/folder>')

  • many documentation improvements (clarification, additional examples (see {{{hg help --verbose}}}), ...)

  • improved PyPy support

  • {{{hg clone --uncompressed}}} is now 3-4x faster on Windows. See the backgroundclose* options in {{{hg help config.worker}}} for more.

A full overview is available on WhatsNew.