Page MenuHomePhabricator
Feed Advanced Search

Oct 26 2022

epriestley closed T13683: Security Guidance: References to Files in Remarkup as Resolved.

There are some remaining non-security bugs with this that I'll follow up on in T13682. I believe the security side of this is now resolved.

Oct 26 2022, 8:03 PM · Guides, Files, Security
epriestley added a comment to T13683: Security Guidance: References to Files in Remarkup .

The details of this attack will be disclosed at a later date, once installs have had some sort of plausible chance to upgrade.

Oct 26 2022, 8:01 PM · Guides, Files, Security

May 27 2022

epriestley triaged T13683: Security Guidance: References to Files in Remarkup as Normal priority.
May 27 2022, 6:13 PM · Guides, Files, Security

Dec 16 2021

epriestley added a comment to T13637: PHP Static Method Variable Scope.

See also T13588.

Dec 16 2021, 10:37 PM · Lint, Guides

Dec 2 2021

cspeckmim updated the task description for T13669: Discourage use of Mailgun as a mail provider.
Dec 2 2021, 11:18 PM · Guides, Mail
epriestley added a revision to T13669: Discourage use of Mailgun as a mail provider: D21738: Document Mailgun as discouraged, and update Postmark remote address blocks.
Dec 2 2021, 10:48 PM · Guides, Mail
epriestley updated the task description for T13669: Discourage use of Mailgun as a mail provider.
Dec 2 2021, 10:42 PM · Guides, Mail
epriestley updated the task description for T13669: Discourage use of Mailgun as a mail provider.
Dec 2 2021, 10:39 PM · Guides, Mail
epriestley added a comment to T13669: Discourage use of Mailgun as a mail provider.

Purely venting, but the advanced version of "click here to schedule a mysterious meeting" is to outright lie -- pretending that you deeply respect the recipient's achievements -- before asking them to schedule a mysterious meeting.

Dec 2 2021, 10:30 PM · Guides, Mail
epriestley triaged T13669: Discourage use of Mailgun as a mail provider as Normal priority.
Dec 2 2021, 10:12 PM · Guides, Mail

Aug 19 2021

epriestley updated the task description for T13664: SSRF and Phabricator.
Aug 19 2021, 5:07 PM · Security, Guides
epriestley triaged T13664: SSRF and Phabricator as Low priority.
Aug 19 2021, 4:41 PM · Security, Guides

Apr 26 2021

cspeckmim added a watcher for Guides: cspeckmim.
Apr 26 2021, 1:05 PM

Apr 25 2021

tycho.tatitscheff added a watcher for Guides: tycho.tatitscheff.
Apr 25 2021, 1:43 AM

Mar 12 2021

epriestley added a comment to T13637: PHP Static Method Variable Scope.

I think lint could reasonably emit two warnings about this:

Mar 12 2021, 7:36 PM · Lint, Guides
epriestley triaged T13637: PHP Static Method Variable Scope as Wishlist priority.
Mar 12 2021, 7:32 PM · Lint, Guides

Oct 19 2020

epriestley added a revision to T13491: Why does Arcanist require "--"?: D21482: Update "arc call-conduit" instructions in Conduit API console for required "--".
Oct 19 2020, 6:54 PM · Guides

Aug 5 2020

epriestley updated the task description for T13241: Guide: SMS is Insecure.
Aug 5 2020, 7:22 PM · Security, Guides

Jul 27 2020

epriestley updated the task description for T13548: Upgrading: Mid 2020 Changes to "arc feature" / "arc branch" / "arc bookmark".
Jul 27 2020, 6:06 PM · Guides, Arcanist

Jul 22 2020

epriestley added a comment to T13545: Upgrading: Mid 2020 Changes to "arc diff".

Please use Discourse to discuss Phabricator.

Jul 22 2020, 11:49 PM · Arcanist, Guides
jbrownEP added a comment to T13545: Upgrading: Mid 2020 Changes to "arc diff".

This task references more details on "Excuses" and "Prompts", but there isn't any. Is there any way to provide context around lint issues?

Jul 22 2020, 11:46 PM · Arcanist, Guides

Jul 21 2020

epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jul 21 2020, 6:24 PM · Guides, Arcanist
epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jul 21 2020, 6:24 PM · Guides, Arcanist

Jul 3 2020

epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jul 3 2020, 8:19 PM · Guides, Arcanist
epriestley updated the task description for T13548: Upgrading: Mid 2020 Changes to "arc feature" / "arc branch" / "arc bookmark".
Jul 3 2020, 7:46 PM · Guides, Arcanist
epriestley updated the task description for T13548: Upgrading: Mid 2020 Changes to "arc feature" / "arc branch" / "arc bookmark".
Jul 3 2020, 7:45 PM · Guides, Arcanist
epriestley updated the task description for T13548: Upgrading: Mid 2020 Changes to "arc feature" / "arc branch" / "arc bookmark".
Jul 3 2020, 7:43 PM · Guides, Arcanist

Jun 9 2020

epriestley moved T13548: Upgrading: Mid 2020 Changes to "arc feature" / "arc branch" / "arc bookmark" from Backlog to vNext on the Arcanist board.
Jun 9 2020, 2:09 AM · Guides, Arcanist
epriestley moved T13545: Upgrading: Mid 2020 Changes to "arc diff" from Backlog to vNext on the Arcanist board.
Jun 9 2020, 2:09 AM · Arcanist, Guides

Jun 8 2020

epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 8 2020, 10:54 PM · Guides, Arcanist
epriestley updated the task description for T13548: Upgrading: Mid 2020 Changes to "arc feature" / "arc branch" / "arc bookmark".
Jun 8 2020, 9:42 PM · Guides, Arcanist
epriestley renamed T13548: Upgrading: Mid 2020 Changes to "arc feature" / "arc branch" / "arc bookmark" from Upgrading: Mid 2020 Changes to "arc feature" / "arc branch" to Upgrading: Mid 2020 Changes to "arc feature" / "arc branch" / "arc bookmark".
Jun 8 2020, 7:34 PM · Guides, Arcanist
epriestley triaged T13548: Upgrading: Mid 2020 Changes to "arc feature" / "arc branch" / "arc bookmark" as Normal priority.
Jun 8 2020, 7:34 PM · Guides, Arcanist
epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 8 2020, 6:40 PM · Guides, Arcanist
epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 8 2020, 1:34 PM · Guides, Arcanist
epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 8 2020, 1:21 PM · Guides, Arcanist

Jun 7 2020

epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 7 2020, 4:22 PM · Guides, Arcanist

Jun 4 2020

epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 4 2020, 5:51 PM · Guides, Arcanist
epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 4 2020, 4:37 PM · Guides, Arcanist
epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 4 2020, 3:39 PM · Guides, Arcanist
epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 4 2020, 12:49 PM · Guides, Arcanist
epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 4 2020, 12:48 PM · Guides, Arcanist
epriestley moved T13547: Upgrading: Mid 2020 Changes to "arc land" from Backlog to arc land on the Arcanist board.
Jun 4 2020, 3:08 AM · Guides, Arcanist
epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 4 2020, 2:51 AM · Guides, Arcanist

Jun 2 2020

epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 2 2020, 9:00 PM · Guides, Arcanist
epriestley updated the task description for T13547: Upgrading: Mid 2020 Changes to "arc land".
Jun 2 2020, 7:11 PM · Guides, Arcanist
epriestley triaged T13547: Upgrading: Mid 2020 Changes to "arc land" as Normal priority.
Jun 2 2020, 7:10 PM · Guides, Arcanist

May 30 2020

epriestley updated the task description for T13545: Upgrading: Mid 2020 Changes to "arc diff".
May 30 2020, 11:11 PM · Arcanist, Guides
epriestley triaged T13545: Upgrading: Mid 2020 Changes to "arc diff" as Low priority.
May 30 2020, 11:05 PM · Arcanist, Guides

Feb 24 2020

epriestley closed T4289: JIRA authenticator JIRA version 5 compatibility, a subtask of T5422: Does Phabricator integrate with JIRA?, as Wontfix.
Feb 24 2020, 9:10 PM · Guides, Doorkeeper
epriestley added a comment to T13188: CircleCI 1.0 sunsets on August 31, 2018; CircleCI 2.0 can not work with Phabricator.

See also PHI1605 (internal), which provides some evidence that:

Feb 24 2020, 5:05 PM · Guides, Harbormaster

Feb 21 2020

epriestley updated the task description for T13491: Why does Arcanist require "--"?.
Feb 21 2020, 12:10 AM · Guides
epriestley updated the task description for T13491: Why does Arcanist require "--"?.
Feb 21 2020, 12:10 AM · Guides
epriestley updated the task description for T13491: Why does Arcanist require "--"?.
Feb 21 2020, 12:09 AM · Guides

Feb 15 2020

epriestley updated the task description for T13491: Why does Arcanist require "--"?.
Feb 15 2020, 5:54 PM · Guides
epriestley updated the task description for T13491: Why does Arcanist require "--"?.
Feb 15 2020, 5:47 PM · Guides
epriestley updated the task description for T13491: Why does Arcanist require "--"?.
Feb 15 2020, 5:43 PM · Guides
epriestley updated the task description for T13491: Why does Arcanist require "--"?.
Feb 15 2020, 5:42 PM · Guides
epriestley updated the task description for T13491: Why does Arcanist require "--"?.
Feb 15 2020, 5:41 PM · Guides
epriestley triaged T13491: Why does Arcanist require "--"? as Low priority.
Feb 15 2020, 5:40 PM · Guides

Jan 14 2020

artms added a comment to T5422: Does Phabricator integrate with JIRA?.

In jira 8.6.1 settings are now in:

  • AdministrationApplicationsApplication links
Jan 14 2020, 3:31 PM · Guides, Doorkeeper

Aug 28 2019

epriestley added a comment to T13376: Write about "add more logging / monitoring / tests".

Another variation of this is "add more documentation", although I think the pattern around this one is more rarely a sort of "problem domain / solution domain mismatch" sort of issue and more often a "human communication" issue, usually with one of these two templates:

Aug 28 2019, 3:39 PM · Guides

Aug 15 2019

epriestley triaged T13377: Write about "how to solve problems with program behavior" as Wishlist priority.
Aug 15 2019, 4:54 PM · Guides
epriestley triaged T13376: Write about "add more logging / monitoring / tests" as Wishlist priority.
Aug 15 2019, 4:42 PM · Guides

May 16 2019

simevo added a comment to T3179: Importing data from external systems (like GitHub, JIRA, Trac, Asana, Trello, etc.).

For all who might need to migrate from trac to Phabricator, feel free to borrow from this bare-bone script: https://gitlab.com/simevo/trac2phab

May 16 2019, 2:27 PM · Guides, Doorkeeper

May 3 2019

epriestley closed T5462: How do I publish Phabricator events into remote systems? as Resolved.

The answer here is now pretty unambiguously "Use Webhooks". feed.http-hooks is formally deprecated, Herald remains a terrible idea, and anyone brave enough to touch Doorkeeper can probably figure things out for themselves.

May 3 2019, 4:57 AM · Guides, Doorkeeper, Feed, Herald

Apr 23 2019

epriestley closed T13274: Guide: Overheated Queries as Resolved.

(This seems stable now, and there's no specific action here.)

Apr 23 2019, 7:34 PM · Infrastructure, Guides

Mar 27 2019

epriestley updated the task description for T13274: Guide: Overheated Queries.
Mar 27 2019, 10:41 PM · Infrastructure, Guides

Mar 19 2019

epriestley closed T13251: Upgrading: PhutilURI Query Parameter Changes as Resolved.

This seems to have quieted down, now.

Mar 19 2019, 8:46 PM · Installing & Upgrading, Guides, Infrastructure

Mar 13 2019

epriestley added a comment to T5422: Does Phabricator integrate with JIRA?.

See PHI1125. Recent versions of JIRA (JIRA 8?) still work with approximately the same instructions, but you have to fill out a modal dialog with about 7 required fields first, and none of the fields have real values. That is, the configuration instructions for recent JIRA are:

Mar 13 2019, 11:16 AM · Guides, Doorkeeper

Feb 22 2019

epriestley added a revision to T13251: Upgrading: PhutilURI Query Parameter Changes: D20204: Fix URI construction of typeahead browse "more" pager.
Feb 22 2019, 10:55 PM · Installing & Upgrading, Guides, Infrastructure
20after4 added a comment to T13251: Upgrading: PhutilURI Query Parameter Changes.

This change broke the search dialog on tags typeaheads...

Feb 22 2019, 9:28 PM · Installing & Upgrading, Guides, Infrastructure

Feb 16 2019

epriestley updated the task description for T13251: Upgrading: PhutilURI Query Parameter Changes.
Feb 16 2019, 2:21 AM · Installing & Upgrading, Guides, Infrastructure

Feb 12 2019

epriestley triaged T13251: Upgrading: PhutilURI Query Parameter Changes as Normal priority.
Feb 12 2019, 10:17 PM · Installing & Upgrading, Guides, Infrastructure

Feb 11 2019

epriestley added a revision to T12101: Phabricator PHP 7 Compatibility: D20138: Improve top-level fatal exception handling in PHP 7+.
Feb 11 2019, 6:05 PM · Infrastructure, Guides

Jan 25 2019

epriestley updated the task description for T13241: Guide: SMS is Insecure.
Jan 25 2019, 3:57 PM · Security, Guides

Jan 24 2019

epriestley added a comment to T6012: Why doesn't Phabricator (or Arcanist, or libphutil) support Composer?.

Not exactly related, but PEAR got compromised: https://news.ycombinator.com/item?id=18987518

Jan 24 2019, 4:54 PM · Guides

Dec 19 2018

epriestley added a comment to T4200: Building OS packages and install scripts.

(Please use Discourse for this sort of discussion.)

Dec 19 2018, 3:50 PM · Guides, Setup
yaneurabeya added a comment to T4200: Building OS packages and install scripts.

It's been several year's since this task has been opened up, and it's not clear what the current progress on this. Is there a way that versioning please be added to GitHub, per the recommendations on https://github.com/Homebrew/homebrew-php/pull/3864 ? I'm not able to install arcanist currently using homebrew because there isn't a stable tagged version newer than one from 2012.

Dec 19 2018, 11:13 AM · Guides, Setup

Dec 17 2018

epriestley closed T13186: Upgrading: Legacy "Can Edit <Field>" policies in Maniphest; requireCapabilities() in TransactionEditor as Resolved.

This appears to be stable and working properly. D19897 removes a straggling guardrail.

Dec 17 2018, 8:46 PM · Security, Policy, ApplicationEditor, Guides, Installing & Upgrading

Dec 13 2018

epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): D19882: Fix construction of two new qsprintf() exceptions.
Dec 13 2018, 7:01 PM · Installing & Upgrading, Infrastructure, Security, Guides

Dec 12 2018

epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): D19872: Fix a stray qsprintf() in the Herald rules engine when recording rule application to objects.
Dec 12 2018, 6:59 PM · Installing & Upgrading, Infrastructure, Security, Guides
epriestley closed T13217: Upgrading: Hardening of qsprintf() as Resolved.

There are probably some stragglers that have yet to turn up, but we appear to have survived this largely unscathed.

Dec 12 2018, 6:19 PM · Installing & Upgrading, Infrastructure, Security, Guides
epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): D19869: Fix some straggling qsprintf() warnings in repository import.
Dec 12 2018, 1:25 PM · Installing & Upgrading, Infrastructure, Security, Guides

Nov 27 2018

urzds added a comment to T5132: Document the special syntax you can use in commit messages to cause effects.

Are colons (:) supported between the keywords and the objects? E.g. Fixes: adcbdef or Depends On: D123?

Nov 27 2018, 7:54 PM · Guides, Diffusion

Nov 25 2018

epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): D19837: Make a Feed query construction less clever/sneaky for new qsprintf() semantics.
Nov 25 2018, 9:40 PM · Installing & Upgrading, Infrastructure, Security, Guides

Nov 17 2018

epriestley updated the task description for T13217: Upgrading: Hardening of qsprintf().
Nov 17 2018, 1:35 AM · Installing & Upgrading, Infrastructure, Security, Guides
epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): Restricted Differential Revision.
Nov 17 2018, 1:21 AM · Installing & Upgrading, Infrastructure, Security, Guides
epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): D19820: Fix some "%Q" behavior in PhortuneMerchantQuery.
Nov 17 2018, 1:20 AM · Installing & Upgrading, Infrastructure, Security, Guides
epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): Restricted Differential Revision.
Nov 17 2018, 1:12 AM · Installing & Upgrading, Infrastructure, Security, Guides

Nov 15 2018

epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): D19814: Continue cleaning up queries in the wake of changes to "%Q".
Nov 15 2018, 2:00 PM · Installing & Upgrading, Infrastructure, Security, Guides
epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): D19812: Use "%P" to protect session key hashes in SessionEngine queries from DarkConsole.
Nov 15 2018, 1:32 PM · Installing & Upgrading, Infrastructure, Security, Guides
epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): D19811: Keep the new "%P" query conversion out of the service call profiler by unmasking later.
Nov 15 2018, 1:28 PM · Installing & Upgrading, Infrastructure, Security, Guides
epriestley updated the task description for T13217: Upgrading: Hardening of qsprintf().
Nov 15 2018, 1:26 PM · Installing & Upgrading, Infrastructure, Security, Guides

Nov 13 2018

epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): D19801: Fix all query warnings in "arc unit --everything".
Nov 13 2018, 6:33 PM · Installing & Upgrading, Infrastructure, Security, Guides
epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): D19800: Add "%Z" (Raw Query) and "%LK" (List of Columns for Keys) to qsprintf().
Nov 13 2018, 6:29 PM · Installing & Upgrading, Infrastructure, Security, Guides
epriestley added a comment to T13217: Upgrading: Hardening of qsprintf().

I'm going to start landing this stuff now. master will start complaining about unsafe queries all over the place (although much less frequently than it was when I first added the warning). Depending on how much complaining still exists on Friday I might make the warning developer-only, but I'm currently hopeful that I can clean up most of it before the next release promotes.

Nov 13 2018, 4:47 PM · Installing & Upgrading, Infrastructure, Security, Guides

Nov 9 2018

epriestley updated the task description for T13217: Upgrading: Hardening of qsprintf().
Nov 9 2018, 12:42 PM · Installing & Upgrading, Infrastructure, Security, Guides

Nov 7 2018

epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): D19790: Continue making application fixes to Phabricator for changes to %Q semantics.
Nov 7 2018, 12:59 PM · Installing & Upgrading, Infrastructure, Security, Guides
epriestley added a revision to T13217: Upgrading: Hardening of qsprintf(): D19789: Update many Phabricator queries for new %Q query semantics.
Nov 7 2018, 12:29 PM · Installing & Upgrading, Infrastructure, Security, Guides