Mercurial 4.5 (2018-02-01)#
Mercurial 4.5.3 (2018-04-04)#
This is a regularly-scheduled bugfix release.
Bug Fixes#
rebase: on abort, don't strip commits that didn't need to be rebased (issue5822)
hgweb: garbage collect on every request
amend: abort if unresolved merge conflicts found (issue5805)
Mercurial 4.5.1 / 4.5.2 (2018-03-06)#
(4.5.2 was released immediately after 4.5.1 to fix a release oversight.)
This is a regularly-scheduled bugfix release.
Security Fixes#
All versions of Mercurial prior to 4.5.2 have vulnerabilities in the HTTP server that allow permissions bypass to:
Perform writes on repositories that should be read-only
Perform reads on repositories that shouldn't allow read access
CVE-2018-1000132 has been assigned these vulnerabilities.
The nature of the vulnerabilities is:
Wire protocol commands that didn't explicitly declare their permissions had no permissions checking done. The
web.{allow-pull, allow-push, deny_read, etc}config options governing access control were never consulted when running these commands. This allowed permissions bypass for impacted commands.The
batchwire protocol command did not list its permission requirements nor did it enforce permissions on individual sub-commands.
The implication of these vulnerabilities is that no permissions checking was performed on commands and this could lead to accessing data that web.* config options were supposed to prevent access to or modifying data (via wire protocol commands that can mutate data) without authorization. A Mercurial HTTP server in its default configuration is supposed to be read-only. However, a well-crafted batch command could invoke commands that perform writes.
The batch write permissions bypass has been present since Mercurial 1.9. The flaw of not checking permissions for wire protocol commands that don't declare their needed permissions has been present since Mercurial 1.0.
Assuming you are running a server without any custom commands provided by extensions, your exposure is unauthorized data access (if relying on the web.* config options to limit access) and unauthorized data mutation via the batch command.
Server operators can detect unauthorized use of the batch command by looking for requests to URLs of the form repo?cmd=batch with arguments containing pushkey or unbundle. This may produce false positives. A more comprehensive check would decode the argument string and verify that pushkey or unbundle are command names (not values). The arguments specified via x-hgarg-<N> request headers can span multiple headers. So advanced attackers could hide the vulnerability by splitting a pushkey or unbundle string across multiple headers. So the only reliable way to detect if this vulnerability is being exploited is to decode these headers like Mercurial does. The format for specifying arguments is documented at https://www.mercurial-scm.org/repo/hg/file/4.5/mercurial/help/internals/wireprotocol.txt#l26. Python code for decoding headers is at https://www.mercurial-scm.org/repo/hg/file/4.5/mercurial/hgweb/protocol.py#l70.
Mercurial 4.5.2 fixes these vulnerabilities by:
Performing permissions checking on all wire protocol commands, not just commands that list their permissions.
Checking permissions on sub-commands issued to the
batchcommand.
Wire protocol commands not declaring wire protocol permissions will be assumed to be read-write commands and a server in its default configuration (which only allows read-only access), will refuse to execute these commands.
For package maintainers needing to backport the fixes, the relevant changesets from 4.5.2 are 2c647da851ed::2ecb0fc535b1. These can be viewed online at e.g. https://www.mercurial-scm.org/repo/hg/rev/2ecb0fc535b1. The author of these commits has backports to 4.4 and 4.3 on a personal fork at https://hg.mozilla.org/users/gszorc_mozilla.com/hg. The backports for 4.4 are a4843835c835::7cf827e5f8af and for 4.3 are db527ae12671::86f9a022ccb8. To obtain these changesets, run e.g. hg pull -r 7cf827e5f8af https://hg.mozilla.org/users/gszorc_mozilla.com/hg.
Backwards Compatibility Changes#
The "batch" wire protocol command now enforces permissions of each invoked sub-command. Wire protocol commands must define their operation type or the "batch" command will assume they can write data and will prevent their execution on HTTP servers unless the HTTP request method is POST, the server is configured to allow pushes, and the (possibly authenticated) HTTP user is authorized to perform a push.
Wire protocol commands not defining their operation type in "wireproto.PERMISSIONS" are now assumed to be used for "push" operations and access control to run those commands is now enforced accordingly.
Bug Fixes#
fileset: don't abort when running copied() on a revision with a removed file
date: fix parsing months
setup: only allow Python 3 from a source checkout (issue5804)
annotate: do not poorly split lines at CR (issue5798)
subrepo: don't attempt to share remote sources (issue5793)
subrepo: activate clone pooling to enable sharing with remote URLs
changegroup: do not delta lfs revisions
revlog: do not use delta for lfs revisions
revlog: resolve lfs rawtext to vanilla rawtext before applying delta
Mercurial 4.5 release#
New Features#
revert --interactive#
The revert command now accepts the flag --interactive to allow reverting only some of the changes to the specified files.
githelp extension#
The githelp extension provides the hg githelp command. This command
attempts to convert a git command to its Mercurial equivalent. The extension
can be useful to Git users new to Mercurial.
Largefiles changes#
largefiles: add a 'debuglfput' command to put largefile into the store
largefiles: add support for 'largefiles://' url scheme
largefiles: allow to run 'debugupgraderepo' on repo with largefiles
largefiles: convert EOL of hgrc before appending to bytes IO
largefiles: explicitly set the source and sink types to 'hg' for lfconvert
largefiles: modernize how capabilities are added to the wire protocol
hgweb changes#
hgweb now shows more information about commits: phase (if it's not public), obsolescence status (with a short explanation and links to the successors) and instabilities (e.g. orphan, phase-divergent or content-divergent).
Client-side graph code has been simplified by delegating more work to the backend, so /graph page is now more in sync with /log page, visually and feature-wise. Unfortunately, this code change means that 3rd-party themes for 4.5+ are required to have graphentry.tmpl template available (copy it from the base theme if you don't use %include and then reference it in map file) and render entries in graph.tmpl -- look at one of the core themes to see what it needs to look like. JS functions that create graph vertices and edges are now available in Graph.prototype, making it possible to call the original functions from custom theme-specific functions if needed.
Graph now shows different symbols for normal, branch-closing, obsolete and unstable commits, and marks currently checked out commit with a circle around its graph node.
There's also now json-graph API endpoint that can be used for rendering commit graph in 3rd-party applications.
Other Changes#
When interactive revert is run against a revision other than the working directory parent, the diff shown is the diff to apply to the working directory, rather than the diff to discard from the working copy. This is in line with related user experiences with 'git' and appears to be less confusing with 'ui.interface=curses'.
Let 'hg rebase' avoid content-divergence by skipping obsolete changesets (and their descendants) when they are present in the rebase set along with one of their successors but none of their successors is in destination.
A new experimental config flag, 'rebase.experimental.inmemory', makes rebase perform an in-memory merge instead of doing it on-disk in the working copy.
The
HGPLAINEXCEPTenvironment variable can now includecolorto allow automatic output colorization in otherwise automated environments.A new unamend command in uncommit extension which undoes the effect of the amend command by creating a new changeset which was there before amend and moving the changes that were amended to the working directory.
A '--abort' flag to merge command to abort the ongoing merge.
An experimental flag '--rev' to 'hg branch' which can be used to change branch of changesets.
bundle2 read I/O significantly improved
bundle2 memory use significantly reduced during read
clonebundle: it is now possible to serve the clonebundle using a git-lfs compatible server.
templatefilters: add slashpath() to convert path separator to slash (Bts:issue5572)
A new experimental config flag, 'inline-color-diff', adds within-line color diff capacity
histedit: add support to output nodechanges using formatter to help with editor integrations
Backwards Compatibility Changes#
log --follow-first -rREV, which is deprecated, now follows the first parent of merge revisions from the specifiedREVjust likelog --follow -rREV.log --follow -rREV FILE..now follows file history across copies and renames.transaction: register summary callbacks only at start of transaction
hgweb's graph view no longer supports browsers that lack <canvas> support
hgweb: only include graph-related data in jsdata variable on /graph pages
graphlog: add another graph node type, unstable, using character
*remove: print message for each file in verbose mode only while using '-A'
Bug Fixes#
Bookmark, whose name is longer than 255, can again be exchanged again between 4.4+ client and servers (Bts:issue5165)
The convert extension works with bzr < 2.6.0 again (Bts:issue5733)
Mercurial will now attempt to use hardlinks on NTFS on Windows (Bts:issue4580)
The revset
x^::is now correctly parsed as(x^)::instead of being an error (Bts:issue5764)Setting the diff.noprefix configuration option no longer breaks the
--statflag onhg diff(Bts:issue5759)hg outgoingnow honors:pushurlpaths from hgrc (Bts:issue5365)log: translate column labels at once (Bts:issue5750)
patch: improve heuristics to not take the word
diffas header (Bts:issue1879)templater: look up symbols/resources as if they were separated (Bts:issue5699)
http and ssh: support for emitting extra debug logs about requests as they happen
API Changes#
bundlerepo.bundlerepository.bundleandbundlerepo.bundlerepository.bundlefileare now prefixed with an underscore.Rename bundlerepo.bundlerepository.bundlefilespos to _cgfilespos.
dirstate no longer provides a 'dirs()' method. To test for the existence of a directory in the dirstate, use 'dirstate.hasdir(dirname)'.
mapping does not contain all template resources. use context.resource() in template functions.
text=False|Trueoption is dropped from the vfs interface because of Python 3 compatibility issue. Useutil.tonativeeol/fromnativeeol()to convert EOL manually.wireproto.streamres.__init__no longer accepts areaderargument. Use thegenargument instead.exchange.getbundlechunks() now returns a 2-tuple instead of just an iterator.
bundle2 parts are no longer seekable by default
memfilectx: the changectx argument is now mandatory in constructor