Page MenuHomePhabricator

Convert Score binaries to use MediaWiki shell restrictions
Closed, ResolvedPublic

Event Timeline

Legoktm created this task.Nov 28 2017, 6:00 PM
Restricted Application added a subscriber: Aklapper. · View Herald TranscriptNov 28 2017, 6:00 PM

Change 393830 had a related patch set uploaded (by Legoktm; owner: Legoktm):
[mediawiki/extensions/Score@master] Enable shell restrictions for lilypond

https://gerrit.wikimedia.org/r/393830

I tested the patch with https://en.wikipedia.org/wiki/Pastime_with_Good_Company and I also set $wgScoreLilypond to point to mediawiki-firejail-lilypond (firejail inside a firejail) and it all worked.

Change 393830 merged by jenkins-bot:
[mediawiki/extensions/Score@master] Enable shell restrictions for all binaries

https://gerrit.wikimedia.org/r/393830

Legoktm renamed this task from Convert "lilypond" to use MediaWiki shell restrictions to Convert Score binaries to use MediaWiki shell restrictions.Dec 4 2017, 4:33 AM

Change 394913 had a related patch set uploaded (by Legoktm; owner: Legoktm):
[operations/mediawiki-config@master] Remove manual firejailing of Score binaries

https://gerrit.wikimedia.org/r/394913

Change 394914 had a related patch set uploaded (by Legoktm; owner: Legoktm):
[operations/puppet@production] mediawiki: Remove Score firejail wrappers

https://gerrit.wikimedia.org/r/394914

TheDJ awarded a token.Dec 4 2017, 9:43 AM
Legoktm closed this task as Resolved.Dec 8 2017, 9:02 PM

There's still a little cleanup to do, but I'll follow-up on that.

Change 394913 merged by jenkins-bot:
[operations/mediawiki-config@master] Remove manual firejailing of Score binaries

https://gerrit.wikimedia.org/r/394913

Mentioned in SAL (#wikimedia-operations) [2017-12-12T00:53:08Z] <legoktm@tin> Synchronized wmf-config/CommonSettings.php: Remove manual firejailing of Score binaries (T181535) (duration: 00m 56s)

Change 394914 merged by Muehlenhoff:
[operations/puppet@production] mediawiki: Remove Score firejail wrappers

https://gerrit.wikimedia.org/r/394914