Page MenuHomeMiraheze

Extension:Score disabled due to multiple security issues
Open, Stalled, LowPublic

Description

See https://phabricator.wikimedia.org/T257066 and https://git.io/JJTNO

This serves as a public task (after fix merged) to let people know why.

Could not execute LilyPond: /dev/null is not an executable file. Make sure $wgScoreLilyPond is set correctly

Is expected and will block rendering of new score content

Revisions and Commits

Event Timeline

RhinosF1 lowered the priority of this task from High to Normal.Jul 3 2020, 17:30
RhinosF1 updated the task description. (Show Details)
RhinosF1 moved this task from Backlog to Deployed Extension Bugs on the Extensions board.
RhinosF1 changed the visibility from "Custom Policy" to "Public (No Login Required)".
RhinosF1 changed the edit policy from "Custom Policy" to "All Users".

We should get more info on Monday.

Score restricted in ManageWiki until it's resolved.

Score restricted in ManageWiki until it's resolved.

This is because we've been informed that further issues have been found with "no fix in sight".

MediaWiki was already pointing at /dev/null for the package so wasn't using it but the package has now been removed from production.

RhinosF1 changed the task status from Open to Stalled.EditedAug 1 2020, 10:41
RhinosF1 lowered the priority of this task from Normal to Low.

Per above, will try and get some more info from Tim upstream later

RhinosF1 renamed this task from Extension:Score disabled due to security issue to Extension:Score disabled due to multiple security issues.Aug 1 2020, 10:42

@Southparkfan: status still remains at unresolved issues with the addition of mem leaks based on the updated I just got.

Are you happy to remain in the disabled and blocking new installs state? Should we add a note by the name in ManageWiki as to why it's disabled?

This feels like it might be remaining off for the long run.

To answer my last comment.

Let's keep the extension disabled, following Tim's advice at https://phabricator.wikimedia.org/T257066#6364537. However, a note must be in place.