##// END OF EJS Templates
dispatch: protect against malicious 'hg serve --stdio' invocations (sec)...
dispatch: protect against malicious 'hg serve --stdio' invocations (sec) Some shared-ssh installations assume that 'hg serve --stdio' is a safe command to run for minimally trusted users. Unfortunately, the messy implementation of argument parsing here meant that trying to access a repo named '--debugger' would give the user a pdb prompt, thereby sidestepping any hoped-for sandboxing. Serving repositories over HTTP(S) is unaffected. We're not currently hardening any subcommands other than 'serve'. If your service exposes other commands to users with arbitrary repository names, it is imperative that you defend against repository names of '--debugger' and anything starting with '--config'. The read-only mode of hg-ssh stopped working because it provided its hook configuration to "hg serve --stdio" via --config parameter. This is banned for security reasons now. This patch switches it to directly call ui.setconfig(). If your custom hosting infrastructure relies on passing --config to "hg serve --stdio", you'll need to find a different way to get that configuration into Mercurial, either by using ui.setconfig() as hg-ssh does in this patch, or by placing an hgrc file someplace where Mercurial will read it. mitrandir@fb.com provided some extra fixes for the dispatch code and for hg-ssh in places that I overlooked.

File last commit:

r29841:d5883fd0 default
r32050:77eaf953 4.1.3 stable
Show More
relink.py
195 lines | 6.4 KiB | text/x-python | PythonLexer
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 # Mercurial extension to provide 'hg relink' command
#
# Copyright (C) 2007 Brendan Cully <brendan@kublai.com>
#
# This software may be used and distributed according to the terms of the
Matt Mackall
Update license to GPLv2+
r10263 # GNU General Public License version 2 or any later version.
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729
"""recreates hardlinks between repository clones"""
timeless
relink: use absolute_import
r28380 from __future__ import absolute_import
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729
timeless
relink: use absolute_import
r28380 import os
import stat
Yuya Nishihara
py3: move up symbol imports to enforce import-checker rules...
r29205 from mercurial.i18n import _
timeless
relink: use absolute_import
r28380 from mercurial import (
cmdutil,
error,
hg,
util,
)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729
Gregory Szorc
relink: declare command using decorator
r21252 cmdtable = {}
command = cmdutil.command(cmdtable)
Augie Fackler
extensions: change magic "shipped with hg" string...
r29841 # Note for extension authors: ONLY specify testedwith = 'ships-with-hg-core' for
Augie Fackler
extensions: document that `testedwith = 'internal'` is special...
r25186 # extensions which SHIP WITH MERCURIAL. Non-mainline extensions should
# be specifying the version(s) of Mercurial they are tested with, or
# leave the attribute unspecified.
Augie Fackler
extensions: change magic "shipped with hg" string...
r29841 testedwith = 'ships-with-hg-core'
Augie Fackler
hgext: mark all first-party extensions as such
r16743
Gregory Szorc
relink: declare command using decorator
r21252 @command('relink', [], _('[ORIGIN]'))
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 def relink(ui, repo, origin=None, **opts):
"""recreate hardlinks between two repositories
Martin Geisler
relink: wrap long lines in docstring
r9886 When repositories are cloned locally, their data files will be
hardlinked so that they only use the space of a single repository.
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729
Martin Geisler
relink: wrap long lines in docstring
r9886 Unfortunately, subsequent pulls into either repository will break
hardlinks for any files touched by the new changesets, even if
both repositories end up pulling the same changes.
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729
Martin Geisler
relink: wrap long lines in docstring
r9886 Similarly, passing --rev to "hg clone" will fail to use any
hardlinks, falling back to a complete copy of the source
repository.
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729
Martin Geisler
relink: wrap long lines in docstring
r9886 This command lets you recreate those hardlinks and reclaim that
wasted space.
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729
Martin Geisler
relink: wrap long lines in docstring
r9886 This repository will be relinked to share space with ORIGIN, which
must be on the same local disk. If ORIGIN is omitted, looks for
"default-relink", then "default", in [paths].
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729
Martin Geisler
relink: wrap long lines in docstring
r9886 Do not attempt any read operations on this repository while the
command is running. (Both repositories will be locked against
writes.)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 """
Augie Fackler
hgext: replace uses of hasattr with util.safehasattr
r14945 if (not util.safehasattr(util, 'samefile') or
not util.safehasattr(util, 'samedevice')):
Pierre-Yves David
error: get Abort from 'error' instead of 'util'...
r26587 raise error.Abort(_('hardlinks are not supported on this system'))
Simon Heimberg
repo: repo isolation, do not pass on repo.ui for creating new repos...
r18825 src = hg.repository(repo.baseui, ui.expandpath(origin or 'default-relink',
Matt Mackall
hg: change various repository() users to use peer() where appropriate...
r14556 origin or 'default'))
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 ui.status(_('relinking %s to %s\n') % (src.store.path, repo.store.path))
Martin Geisler
relink: avoid trying to lock the same repo twice
r13657 if repo.root == src.root:
ui.status(_('there is nothing to relink\n'))
return
Simon Heimberg
relink: abort earlier when on different devices (issue3916)...
r20083 if not util.samedevice(src.store.path, repo.store.path):
# No point in continuing
Pierre-Yves David
error: get Abort from 'error' instead of 'util'...
r26587 raise error.Abort(_('source and destination are on different devices'))
Simon Heimberg
relink: abort earlier when on different devices (issue3916)...
r20083
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 locallock = repo.lock()
try:
remotelock = src.lock()
try:
timeless
relink/progress: Adding progress for collecting stage
r11355 candidates = sorted(collect(src, ui))
Siddharth Agarwal
Add support for relinking on Windows....
r10218 targets = prune(candidates, src.store.path, repo.store.path, ui)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 do_relink(src.store.path, repo.store.path, targets, ui)
finally:
remotelock.release()
finally:
locallock.release()
def collect(src, ui):
seplen = len(os.path.sep)
candidates = []
timeless
relink/progress: Adding progress for collecting stage
r11355 live = len(src['tip'].manifest())
# Your average repository has some files which were deleted before
# the tip revision. We account for that by assuming that there are
# 3 tracked files for every 2 live files as of the tip version of
# the repository.
#
# mozilla-central as of 2010-06-10 had a ratio of just over 7:5.
total = live * 3 // 2
src = src.store.path
pos = 0
timeless@mozdev.org
l10n: use %d instead of %s for numbers
r26778 ui.status(_("tip has %d files, estimated total number of files: %d\n")
timeless
relink/progress: Adding progress for collecting stage
r11355 % (live, total))
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 for dirpath, dirnames, filenames in os.walk(src):
Martin Geisler
relink: ensure deterministic directory walk in collect
r11357 dirnames.sort()
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 relpath = dirpath[len(src) + seplen:]
Martin Geisler
relink: ensure deterministic directory walk in collect
r11357 for filename in sorted(filenames):
Brodie Rao
cleanup: "not x in y" -> "x not in y"
r16686 if filename[-2:] not in ('.d', '.i'):
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 continue
st = os.stat(os.path.join(dirpath, filename))
if not stat.S_ISREG(st.st_mode):
continue
timeless
relink/progress: Adding progress for collecting stage
r11355 pos += 1
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 candidates.append((os.path.join(relpath, filename), st))
timeless
relink/progress: Adding progress for collecting stage
r11355 ui.progress(_('collecting'), pos, filename, _('files'), total)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729
timeless
relink/progress: Adding progress for collecting stage
r11355 ui.progress(_('collecting'), None)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 ui.status(_('collected %d candidate storage files\n') % len(candidates))
return candidates
Siddharth Agarwal
Add support for relinking on Windows....
r10218 def prune(candidates, src, dst, ui):
def linkfilter(src, dst, st):
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 try:
ts = os.stat(dst)
except OSError:
# Destination doesn't have this file?
return False
Siddharth Agarwal
Add support for relinking on Windows....
r10218 if util.samefile(src, dst):
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 return False
Siddharth Agarwal
Add support for relinking on Windows....
r10218 if not util.samedevice(src, dst):
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 # No point in continuing
Pierre-Yves David
error: get Abort from 'error' instead of 'util'...
r26587 raise error.Abort(
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 _('source and destination are on different devices'))
if st.st_size != ts.st_size:
return False
return st
targets = []
timeless
relink/progress: Adding progress for pruning stage
r11354 total = len(candidates)
pos = 0
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 for fn, st in candidates:
timeless
relink/progress: Adding progress for pruning stage
r11354 pos += 1
Siddharth Agarwal
Add support for relinking on Windows....
r10218 srcpath = os.path.join(src, fn)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 tgt = os.path.join(dst, fn)
Siddharth Agarwal
Add support for relinking on Windows....
r10218 ts = linkfilter(srcpath, tgt, st)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 if not ts:
Matt Mackall
check-code: don't mark debug messages for translation
r14709 ui.debug('not linkable: %s\n' % fn)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 continue
targets.append((fn, ts.st_size))
timeless
progress: dropping superfluous space from units
r12744 ui.progress(_('pruning'), pos, fn, _('files'), total)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729
timeless
relink/progress: Adding progress for pruning stage
r11354 ui.progress(_('pruning'), None)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 ui.status(_('pruned down to %d probably relinkable files\n') % len(targets))
return targets
def do_relink(src, dst, files, ui):
def relinkfile(src, dst):
bak = dst + '.bak'
os.rename(dst, bak)
try:
Adrian Buehlmann
rename util.os_link to oslink
r14235 util.oslink(src, dst)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 except OSError:
os.rename(bak, dst)
raise
os.remove(bak)
CHUNKLEN = 65536
relinked = 0
savedbytes = 0
pos = 0
total = len(files)
for f, sz in files:
pos += 1
source = os.path.join(src, f)
tgt = os.path.join(dst, f)
Siddharth Agarwal
Add support for relinking on Windows....
r10218 # Binary mode, so that read() works correctly, especially on Windows
sfp = file(source, 'rb')
dfp = file(tgt, 'rb')
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 sin = sfp.read(CHUNKLEN)
while sin:
din = dfp.read(CHUNKLEN)
if sin != din:
break
sin = sfp.read(CHUNKLEN)
Siddharth Agarwal
Add support for relinking on Windows....
r10218 sfp.close()
dfp.close()
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 if sin:
Matt Mackall
check-code: don't mark debug messages for translation
r14709 ui.debug('not linkable: %s\n' % f)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 continue
try:
relinkfile(source, tgt)
timeless
progress: dropping superfluous space from units
r12744 ui.progress(_('relinking'), pos, f, _('files'), total)
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729 relinked += 1
savedbytes += sz
Gregory Szorc
global: mass rewrite to use modern exception syntax...
r25660 except OSError as inst:
Martin Geisler
relink: do not translate format string with no text
r9790 ui.warn('%s: %s\n' % (tgt, str(inst)))
Jesse Glick
Issue919: add a standard extension to recreate hardlinks between repositories....
r9729
Matt Mackall
progress: drop extra args for pos=None calls (issue2087)
r10724 ui.progress(_('relinking'), None)
Augie Fackler
relink: properly use the progress API
r10424
Martin Geisler
relink: format reclaimed byte count nicely
r13656 ui.status(_('relinked %d files (%s reclaimed)\n') %
(relinked, util.bytecount(savedbytes)))