Page MenuHomePhabricator

Provide an explicit "-R" flag to "hg serve"

Authored by epriestley on Sep 15 2017, 12:53 PM.




The Mercurial commit is helpful in particular:

We weren't vulnerable to the security issue (users can not control any part of the command) but pass the working directory explicitly to get past the new safety check.

I left setCWD() in place (a few lines below) just because it can't hurt, and in some other contexts it sometimes matter (for example, if commit hooks execute, they might inherit the parent CWD here or in other VCSes).

Test Plan
  • Cloned from a Mercurial repo locally over HTTP.
  • Verified that SSH cloning already uses -R (it does, see DiffusionMercurialServeSSHWorkflow).
  • Did not actually upgrade to Mercurial 4.0/4.1.3 to completely verify this, but a user in the Discourse thread asserted that a substantially similar fix worked correctly.

Diff Detail

rP Phabricator
Automatic diff as part of commit; lint not applicable.
Automatic diff as part of commit; unit tests not applicable.

Event Timeline

epriestley created this revision.Sep 15 2017, 12:53 PM
amckinley accepted this revision.Sep 15 2017, 3:40 PM
This revision is now accepted and ready to land.Sep 15 2017, 3:40 PM
This revision was automatically updated to reflect the committed changes.