##// END OF EJS Templates
dispatch: protect against malicious 'hg serve --stdio' invocations (sec)...
dispatch: protect against malicious 'hg serve --stdio' invocations (sec) Some shared-ssh installations assume that 'hg serve --stdio' is a safe command to run for minimally trusted users. Unfortunately, the messy implementation of argument parsing here meant that trying to access a repo named '--debugger' would give the user a pdb prompt, thereby sidestepping any hoped-for sandboxing. Serving repositories over HTTP(S) is unaffected. We're not currently hardening any subcommands other than 'serve'. If your service exposes other commands to users with arbitrary repository names, it is imperative that you defend against repository names of '--debugger' and anything starting with '--config'. The read-only mode of hg-ssh stopped working because it provided its hook configuration to "hg serve --stdio" via --config parameter. This is banned for security reasons now. This patch switches it to directly call ui.setconfig(). If your custom hosting infrastructure relies on passing --config to "hg serve --stdio", you'll need to find a different way to get that configuration into Mercurial, either by using ui.setconfig() as hg-ssh does in this patch, or by placing an hgrc file someplace where Mercurial will read it. mitrandir@fb.com provided some extra fixes for the dispatch code and for hg-ssh in places that I overlooked.

File last commit:

r30556:c059286a default
r32050:77eaf953 4.1.3 stable
Show More
test-verify.t
319 lines | 8.6 KiB | text/troff | Tads3Lexer
Nicolas Dumazet
tests: unify test-verify
r11787 prepare repo
$ hg init a
$ cd a
$ echo "some text" > FOO.txt
$ echo "another text" > bar.txt
$ echo "more text" > QUICK.txt
$ hg add
adding FOO.txt
adding QUICK.txt
adding bar.txt
$ hg ci -mtest1
verify
$ hg verify
checking changesets
checking manifests
crosschecking files in changesets and manifests
checking files
3 files, 1 changesets, 3 total revisions
verify with journal
$ touch .hg/store/journal
$ hg verify
abandoned transaction found - run hg recover
checking changesets
checking manifests
crosschecking files in changesets and manifests
checking files
3 files, 1 changesets, 3 total revisions
$ rm .hg/store/journal
introduce some bugs in repo
$ cd .hg/store/data
$ mv _f_o_o.txt.i X_f_o_o.txt.i
$ mv bar.txt.i xbar.txt.i
$ rm _q_u_i_c_k.txt.i
$ hg verify
checking changesets
checking manifests
crosschecking files in changesets and manifests
checking files
Matt Mackall
verify: clarify misleading fncache message...
r25627 warning: revlog 'data/FOO.txt.i' not in fncache!
Nicolas Dumazet
tests: unify test-verify
r11787 0: empty or missing FOO.txt
Martin von Zweigbergk
verify: use similar language for missing manifest and file revisions...
r28114 FOO.txt@0: manifest refers to unknown revision f62022d3d590
Matt Mackall
verify: clarify misleading fncache message...
r25627 warning: revlog 'data/QUICK.txt.i' not in fncache!
Nicolas Dumazet
tests: unify test-verify
r11787 0: empty or missing QUICK.txt
Martin von Zweigbergk
verify: use similar language for missing manifest and file revisions...
r28114 QUICK.txt@0: manifest refers to unknown revision 88b857db8eba
Matt Mackall
verify: clarify misleading fncache message...
r25627 warning: revlog 'data/bar.txt.i' not in fncache!
Nicolas Dumazet
tests: unify test-verify
r11787 0: empty or missing bar.txt
Martin von Zweigbergk
verify: use similar language for missing manifest and file revisions...
r28114 bar.txt@0: manifest refers to unknown revision 256559129457
Nicolas Dumazet
tests: unify test-verify
r11787 3 files, 1 changesets, 0 total revisions
Matt Mackall
verify: clarify misleading fncache message...
r25627 3 warnings encountered!
Gregory Szorc
verify: print hint to run debugrebuildfncache...
r25653 hint: run "hg debugrebuildfncache" to recover from corrupt fncache
Matt Mackall
verify: clarify misleading fncache message...
r25627 6 integrity errors encountered!
Nicolas Dumazet
tests: unify test-verify
r11787 (first damaged changeset appears to be 0)
Matt Mackall
tests: add exit codes to unified tests
r12316 [1]
Nicolas Dumazet
tests: unify test-verify
r11787
Mads Kiilerich
tests: cleanup of tests that got lost in their own nested directories...
r16912 $ cd ../../..
Nicolas Dumazet
tests: unify test-verify
r11787 $ cd ..
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110 Set up a repo for testing missing revlog entries
$ hg init missing-entries
$ cd missing-entries
$ echo 0 > file
$ hg ci -Aqm0
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store .hg/store-partial
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110 $ echo 1 > file
$ hg ci -Aqm1
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store .hg/store-full
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Entire changelog missing
$ rm .hg/store/00changelog.*
$ hg verify -q
0: empty or missing changelog
manifest@0: d0b6632564d4 not in changesets
manifest@1: 941fc4534185 not in changesets
3 integrity errors encountered!
(first damaged changeset appears to be 0)
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Entire manifest log missing
$ rm .hg/store/00manifest.*
$ hg verify -q
0: empty or missing manifest
1 integrity errors encountered!
(first damaged changeset appears to be 0)
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Entire filelog missing
$ rm .hg/store/data/file.*
$ hg verify -q
warning: revlog 'data/file.i' not in fncache!
0: empty or missing file
Martin von Zweigbergk
verify: use similar language for missing manifest and file revisions...
r28114 file@0: manifest refers to unknown revision 362fef284ce2
file@1: manifest refers to unknown revision c10f2164107d
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110 1 warnings encountered!
hint: run "hg debugrebuildfncache" to recover from corrupt fncache
3 integrity errors encountered!
(first damaged changeset appears to be 0)
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Entire changelog and manifest log missing
$ rm .hg/store/00changelog.*
$ rm .hg/store/00manifest.*
$ hg verify -q
warning: orphan revlog 'data/file.i'
1 warnings encountered!
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Entire changelog and filelog missing
$ rm .hg/store/00changelog.*
$ rm .hg/store/data/file.*
$ hg verify -q
0: empty or missing changelog
manifest@0: d0b6632564d4 not in changesets
manifest@1: 941fc4534185 not in changesets
warning: revlog 'data/file.i' not in fncache!
?: empty or missing file
Martin von Zweigbergk
verify: use similar language for missing manifest and file revisions...
r28114 file@0: manifest refers to unknown revision 362fef284ce2
file@1: manifest refers to unknown revision c10f2164107d
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110 1 warnings encountered!
hint: run "hg debugrebuildfncache" to recover from corrupt fncache
6 integrity errors encountered!
(first damaged changeset appears to be 0)
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Entire manifest log and filelog missing
$ rm .hg/store/00manifest.*
$ rm .hg/store/data/file.*
$ hg verify -q
0: empty or missing manifest
warning: revlog 'data/file.i' not in fncache!
0: empty or missing file
1 warnings encountered!
hint: run "hg debugrebuildfncache" to recover from corrupt fncache
2 integrity errors encountered!
(first damaged changeset appears to be 0)
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Changelog missing entry
$ cp -f .hg/store-partial/00changelog.* .hg/store
$ hg verify -q
manifest@?: rev 1 points to nonexistent changeset 1
manifest@?: 941fc4534185 not in changesets
file@?: rev 1 points to nonexistent changeset 1
(expected 0)
1 warnings encountered!
3 integrity errors encountered!
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Manifest log missing entry
$ cp -f .hg/store-partial/00manifest.* .hg/store
$ hg verify -q
Martin von Zweigbergk
verify: include "manifest" prefix in a few more places...
r28113 manifest@1: changeset refers to unknown revision 941fc4534185
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110 file@1: c10f2164107d not in manifests
2 integrity errors encountered!
(first damaged changeset appears to be 1)
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Filelog missing entry
$ cp -f .hg/store-partial/data/file.* .hg/store/data
$ hg verify -q
Martin von Zweigbergk
verify: use similar language for missing manifest and file revisions...
r28114 file@1: manifest refers to unknown revision c10f2164107d
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110 1 integrity errors encountered!
(first damaged changeset appears to be 1)
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Changelog and manifest log missing entry
$ cp -f .hg/store-partial/00changelog.* .hg/store
$ cp -f .hg/store-partial/00manifest.* .hg/store
$ hg verify -q
file@?: rev 1 points to nonexistent changeset 1
(expected 0)
file@?: c10f2164107d not in manifests
1 warnings encountered!
2 integrity errors encountered!
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Changelog and filelog missing entry
$ cp -f .hg/store-partial/00changelog.* .hg/store
$ cp -f .hg/store-partial/data/file.* .hg/store/data
$ hg verify -q
manifest@?: rev 1 points to nonexistent changeset 1
manifest@?: 941fc4534185 not in changesets
Martin von Zweigbergk
verify: use similar language for missing manifest and file revisions...
r28114 file@?: manifest refers to unknown revision c10f2164107d
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110 3 integrity errors encountered!
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Manifest and filelog missing entry
$ cp -f .hg/store-partial/00manifest.* .hg/store
$ cp -f .hg/store-partial/data/file.* .hg/store/data
$ hg verify -q
Martin von Zweigbergk
verify: include "manifest" prefix in a few more places...
r28113 manifest@1: changeset refers to unknown revision 941fc4534185
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110 1 integrity errors encountered!
(first damaged changeset appears to be 1)
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Corrupt changelog base node to cause failure to read revision
$ printf abcd | dd conv=notrunc of=.hg/store/00changelog.i bs=1 seek=16 \
> 2> /dev/null
$ hg verify -q
0: unpacking changeset 08b1860757c2: * (glob)
manifest@?: rev 0 points to unexpected changeset 0
manifest@?: d0b6632564d4 not in changesets
file@?: rev 0 points to unexpected changeset 0
(expected 1)
1 warnings encountered!
4 integrity errors encountered!
(first damaged changeset appears to be 0)
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Corrupt manifest log base node to cause failure to read revision
$ printf abcd | dd conv=notrunc of=.hg/store/00manifest.i bs=1 seek=16 \
> 2> /dev/null
$ hg verify -q
Martin von Zweigbergk
verify: include "manifest" prefix in a few more places...
r28113 manifest@0: reading delta d0b6632564d4: * (glob)
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110 file@0: 362fef284ce2 not in manifests
2 integrity errors encountered!
(first damaged changeset appears to be 0)
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
Corrupt filelog base node to cause failure to read revision
$ printf abcd | dd conv=notrunc of=.hg/store/data/file.i bs=1 seek=16 \
> 2> /dev/null
$ hg verify -q
file@0: unpacking 362fef284ce2: * (glob)
1 integrity errors encountered!
(first damaged changeset appears to be 0)
[1]
Jun Wu
tests: replace "cp -r" with "cp -R"...
r30556 $ cp -R .hg/store-full/. .hg/store
Martin von Zweigbergk
tests: add tests for missing revlogs and revlog entries...
r28110
$ cd ..
Patrick Mezard
verify: do not choke on valid changelog without manifest...
r17385 test changelog without a manifest
Nicolas Dumazet
tests: unify test-verify
r11787
$ hg init b
$ cd b
Patrick Mezard
verify: do not choke on valid changelog without manifest...
r17385 $ hg branch foo
marked working directory as branch foo
(branches are permanent and global, did you want a bookmark?)
$ hg ci -m branchfoo
$ hg verify
checking changesets
checking manifests
crosschecking files in changesets and manifests
checking files
0 files, 1 changesets, 0 total revisions
test revlog corruption
Nicolas Dumazet
tests: unify test-verify
r11787
$ touch a
$ hg add a
$ hg ci -m a
$ echo 'corrupted' > b
$ dd if=.hg/store/data/a.i of=start bs=1 count=20 2>/dev/null
$ cat start b > .hg/store/data/a.i
$ hg verify
checking changesets
checking manifests
crosschecking files in changesets and manifests
checking files
Patrick Mezard
verify: do not choke on valid changelog without manifest...
r17385 a@1: broken revlog! (index data/a.i is corrupted)
Nicolas Dumazet
tests: unify test-verify
r11787 warning: orphan revlog 'data/a.i'
Patrick Mezard
verify: do not choke on valid changelog without manifest...
r17385 1 files, 2 changesets, 0 total revisions
Nicolas Dumazet
tests: unify test-verify
r11787 1 warnings encountered!
1 integrity errors encountered!
Patrick Mezard
verify: do not choke on valid changelog without manifest...
r17385 (first damaged changeset appears to be 1)
Matt Mackall
tests: add exit codes to unified tests
r12316 [1]
Nicolas Dumazet
tests: unify test-verify
r11787
Thomas Arendsen Hein
merge with stable
r12172 $ cd ..
test revlog format 0
Matt Mackall
tests: drop explicit $TESTDIR from executables...
r25472 $ revlog-formatv0.py
Thomas Arendsen Hein
merge with stable
r12172 $ cd formatv0
$ hg verify
repository uses revlog format 0
checking changesets
checking manifests
crosschecking files in changesets and manifests
checking files
1 files, 1 changesets, 1 total revisions
Mads Kiilerich
tests: cleanup of tests that got lost in their own nested directories...
r16912 $ cd ..