Page MenuHomePhabricator

RhinosF1 (Samuel)
Volunteer Configurator

Today

  • No visible events.

Tomorrow

  • No visible events.

Wednesday

  • No visible events.

User Details

User Since
Dec 27 2018, 1:42 PM (362 w, 4 d)
Availability
Available
IRC Nick
RhinosF1
LDAP User
RhinosF1
MediaWiki User
RhinosF1 [ Global Accounts ]

See meta.wikimedia.org/wiki/User:RhinosF1

A list of valid alts is at https://meta.wikimedia.org/wiki/User:RhinosF1/Alts

Recent Activity

Fri, Nov 28

RhinosF1 renamed T411235: Beta cluster scap using php8.1 container; php8.2 is now required from Beta cluster is running an unsupported version of PHP to Beta cluster CI is running an unsupported version of PHP.
Fri, Nov 28, 6:50 AM · User-bd808, ci-test-error, Beta-Cluster-Infrastructure
RhinosF1 added a comment to T408275: 1.46.0-wmf.5 deployment blockers.

FYI - Beta scap is broken due to T411235: Beta cluster scap using php8.1 container; php8.2 is now required

Fri, Nov 28, 6:46 AM · Release-Engineering-Team (Priority Backlog 📥), Essential-Work, Release, Train Deployments
RhinosF1 created T411235: Beta cluster scap using php8.1 container; php8.2 is now required.
Fri, Nov 28, 6:44 AM · User-bd808, ci-test-error, Beta-Cluster-Infrastructure

Nov 2 2025

RhinosF1 added a project to T409014: Add English Gyaanipedia to Wikistats: VPS-project-Wikistats.
Nov 2 2025, 8:39 PM · VPS-project-Wikistats

Oct 17 2025

RhinosF1 added a member for Trusted-Contributors: TMWYK.
Oct 17 2025, 7:13 PM

Oct 9 2025

RhinosF1 added a project to T406895: WikiSEO cannot set an external URL as the image if $wgAllowExternalImages is set to true: affects-Miraheze.
Oct 9 2025, 4:06 PM · affects-Miraheze, WikiSEO

Aug 27 2025

RhinosF1 closed T403052: Newly-added member of deployment-prep is not in bastion project, a subtask of T379550: openstack: keystone may be failing to add users to the bastion project, as Resolved.
Aug 27 2025, 3:35 PM · Cloud-VPS, User-aborrero, cloud-services-team
RhinosF1 closed T403052: Newly-added member of deployment-prep is not in bastion project as Resolved.
Aug 27 2025, 3:35 PM · Cloud-VPS, cloud-services-team

Aug 18 2025

RhinosF1 added a project to T402226: User email was not updated in phab after updating on-wiki: Release-Engineering-Team.
Aug 18 2025, 8:21 PM · Release-Engineering-Team, Phabricator
RhinosF1 added a project to T402226: User email was not updated in phab after updating on-wiki: Phabricator.
Aug 18 2025, 8:21 PM · Release-Engineering-Team, Phabricator
RhinosF1 added a comment to T402226: User email was not updated in phab after updating on-wiki.

Phabricator is a completely separate system with a separate authentication system.

Aug 18 2025, 8:20 PM · Release-Engineering-Team, Phabricator

Aug 7 2025

RhinosF1 added a comment to T397900: Warning: User::loadFromSession called before the end of Setup.php.

The second fix (the MediaWiki core one) seems to reduce many more logs than the other one (though both are still needed).

For example https://logstash.wikimedia.org/goto/1204feae3a5687f4dc1e81bc7fd37a3b shows all such warnings fixed by the second patch (2 million in the last week).

Therefore, we should probably also backport the fix to MediaWiki core as well to fix the logs for affects-Miraheze.

Aug 7 2025, 2:55 PM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Platform-Team (Radar), Trust and Safety Product Team, affects-Miraheze, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 added a comment to T397900: Warning: User::loadFromSession called before the end of Setup.php.

There are also a million other such warnings in the last week, but these do not appear to be caused by us (instead the Vector (legacy skin) skin).

I guess that should be split off into another task then

Aug 7 2025, 2:54 PM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Platform-Team (Radar), Trust and Safety Product Team, affects-Miraheze, MediaWiki-extensions-CentralAuth, GlobalBlocking

Aug 4 2025

RhinosF1 updated subscribers of T401099: CVE-2025-61638: Sanitizer::validateAttributes data-XSS.
Aug 4 2025, 11:10 AM · MW-1.44-release, MW-1.43-release, MW-1.39-release, Content-Transform-Team (Work In Progress), SecTeam-Processed, Vuln-XSS, MediaWiki-Parser, Security, Security-Team

Jul 10 2025

RhinosF1 updated the task description for T397776: Write and send supplementary release announcement for extensions and skins with security patches (1.39.14/1.43.4/1.44.1).
Jul 10 2025, 7:50 AM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Jul 9 2025

RhinosF1 updated the task description for T399132: Add security reports from 1.39.13/1.42.7/1.43.2/1.44.0 (+ extension supplement) to security hall of fame.
Jul 9 2025, 8:57 PM · SecTeam-Processed, affects-Miraheze, Security-Team
RhinosF1 updated the task description for T399132: Add security reports from 1.39.13/1.42.7/1.43.2/1.44.0 (+ extension supplement) to security hall of fame.
Jul 9 2025, 8:55 PM · SecTeam-Processed, affects-Miraheze, Security-Team
RhinosF1 updated the task description for T397776: Write and send supplementary release announcement for extensions and skins with security patches (1.39.14/1.43.4/1.44.1).
Jul 9 2025, 8:48 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 created T399132: Add security reports from 1.39.13/1.42.7/1.43.2/1.44.0 (+ extension supplement) to security hall of fame.
Jul 9 2025, 8:43 PM · SecTeam-Processed, affects-Miraheze, Security-Team

Jul 7 2025

RhinosF1 updated subscribers of T392341: CVE-2025-53483, CVE-2025-53484, CVE-2025-53485: SecurePoll is vulnerable to XSS, CSRF, and lack of authorisation.
Jul 7 2025, 8:01 PM · Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, Patch-For-Review, Trust and Safety Product Team, Vuln-BrokenAccessControl, affects-Miraheze, Vuln-CSRF, Vuln-XSS, MediaWiki-extensions-SecurePoll, Security, Security-Team

Jul 5 2025

RhinosF1 added a comment to T398753: Too Many Requests Error on certain useragents (QtWebEngine, outdated chromium based browsers, Safari 605).

I suspect it's similar to https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/message/3DNR7FALKHAU4L5ZUBRNP4Q4YWXLGABB/

Jul 5 2025, 2:47 PM · Traffic

Jul 3 2025

RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

I'm extremely late adding them so if I'm too late then apologies but I added the 2 other ManageWiki CVEs that I forgot to add here

Since they are tracked outside of Phab/Gerrit and have CVEs assigned and merged patches already, it should be fairly trivial to include them for this release.

Thanks, I added the 5 CVEs from the last citizen release too. I'll try and think of a good way of tracking the ones we find that are from non-Wikimedia maintained extensions. It shouldn't be too difficult now both me and @Paladox have security access to create a Miraheze equivalent we can sync up to here close to the release for the next one. Obviously not sharing anything from here the other way around, just us sharing up to you.

Jul 3 2025, 6:11 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 6:02 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:55 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:53 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:51 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:51 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

T394869: CVE-2025-7056: Stored XSS through a system message in UrlShortener and T394612: CVE-2025-7057: Stored XSS through a system message in Extension:Quiz are WMF tracked and missing off the list too

Jul 3 2025, 12:22 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 12:21 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated subscribers of T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

I'm extremely late adding them so if I'm too late then apologies but I added the 2 other ManageWiki CVEs that I forgot to add here

Since they are tracked outside of Phab/Gerrit and have CVEs assigned and merged patches already, it should be fairly trivial to include them for this release.

Jul 3 2025, 12:17 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 12:12 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Jul 2 2025

RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

I'm extremely late adding them so if I'm too late then apologies but I added the 2 other ManageWiki CVEs that I forgot to add here

Jul 2 2025, 4:34 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 2 2025, 4:33 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

Subject: MediaWiki Extensions and Skins Security Release Supplement (1.39.13/1.42.7/1.43.2)

Greetings-

With the security/maintenance release of MediaWiki 1.39.13/1.42.7/1.43.2, we would also like to provide this supplementary announcement of MediaWiki extensions and skins with now-public Phabricator tasks, security patches and backports [1]:

ManageWiki
+ (https://github.com/miraheze/ManageWiki/security/advisories/GHSA-gg42-cv66-f5x7, CVE-2025-32956) - SQL injection vulnerability in NamespaceMigrationJob
https://github.com/miraheze/ManageWiki/commit/f504ed8eeb59b57ebb90f93cd44f23da4c5bc4c9

The Wikimedia Security Team recommends updating these extensions and/or skins to the current master branch or relevant, supported release branch [2] as soon as possible. Some of the referenced Phabricator tasks above _may_ still be private. Unfortunately, when security issues are reported, sometimes sensitive information is exposed and since Phabricator is historical, we cannot make these tasks public without exposing this sensitive information. If you have any additional questions or concerns regarding this update, please feel free to contact security@wikimedia.org or file a security task within Phabricator [3].

[1] https://phabricator.wikimedia.org/T389312
[2] https://www.mediawiki.org/wiki/Version_lifecycle
[3] https://www.mediawiki.org/wiki/Reporting_security_bugs

Jul 2 2025, 4:29 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Jun 29 2025

RhinosF1 updated subscribers of T394614: New upstream release for Pywikibot.

@rook used to be, I created https://github.com/toolforge/paws/pull/488

Jun 29 2025, 4:58 PM · User-RhinosF1, PAWS

Jun 26 2025

RhinosF1 updated the task description for T397900: Warning: User::loadFromSession called before the end of Setup.php.
Jun 26 2025, 7:02 AM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Platform-Team (Radar), Trust and Safety Product Team, affects-Miraheze, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 updated the task description for T397900: Warning: User::loadFromSession called before the end of Setup.php.
Jun 26 2025, 6:54 AM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Platform-Team (Radar), Trust and Safety Product Team, affects-Miraheze, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 removed a project from T397900: Warning: User::loadFromSession called before the end of Setup.php: Wikimedia-production-error.
Jun 26 2025, 6:50 AM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Platform-Team (Radar), Trust and Safety Product Team, affects-Miraheze, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 created T397900: Warning: User::loadFromSession called before the end of Setup.php.
Jun 26 2025, 6:50 AM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Platform-Team (Radar), Trust and Safety Product Team, affects-Miraheze, MediaWiki-extensions-CentralAuth, GlobalBlocking

Jun 24 2025

RhinosF1 added a comment to T385811: Vector should not direct third-party wikis to report dark mode issues to MW.o.

It's saddening to see this antipattern again after years of MediaViewer third-party misconfiguration issues (mis)filed in Wikimedia Phabricator due to hardcoding a Wikimedia URI in an extension that can also be used outside of Wikimedia.

Jun 24 2025, 10:59 AM · Verified, MW-1.45-notes (1.45.0-wmf.17; 2025-09-02), Reader Experience Team, Readers Essential Work 2025, MW-1.44-release, Patch-For-Review, affects-Miraheze, good first task, patch-welcome, WikimediaMessages, MW-1.43-release, Vector 2022
RhinosF1 added a comment to T397679: Non Wikimedia wikis users report dark mode issues on mediawiki.org and causing IP leaks..

There is already a task for this. I don't think it's a security issue or there's need to suppress IPs.

Jun 24 2025, 7:22 AM · SecTeam-Processed, affects-Miraheze
RhinosF1 merged T397679: Non Wikimedia wikis users report dark mode issues on mediawiki.org and causing IP leaks. into T385811: Vector should not direct third-party wikis to report dark mode issues to MW.o.
Jun 24 2025, 7:20 AM · Verified, MW-1.45-notes (1.45.0-wmf.17; 2025-09-02), Reader Experience Team, Readers Essential Work 2025, MW-1.44-release, Patch-For-Review, affects-Miraheze, good first task, patch-welcome, WikimediaMessages, MW-1.43-release, Vector 2022
RhinosF1 merged task T397679: Non Wikimedia wikis users report dark mode issues on mediawiki.org and causing IP leaks. into T385811: Vector should not direct third-party wikis to report dark mode issues to MW.o.
Jun 24 2025, 7:20 AM · SecTeam-Processed, affects-Miraheze

Jun 11 2025

RhinosF1 updated subscribers of T396413: CVE-2025-53497: Stored XSS in RelatedArticles.
Jun 11 2025, 3:34 PM · Web-Team, RelatedArticles, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 updated subscribers of T396413: CVE-2025-53497: Stored XSS in RelatedArticles.
Jun 11 2025, 3:34 PM · Web-Team, RelatedArticles, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 added a comment to T396413: CVE-2025-53497: Stored XSS in RelatedArticles.
Jun 11 2025, 3:33 PM · Web-Team, RelatedArticles, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 added a comment to T396413: CVE-2025-53497: Stored XSS in RelatedArticles.

...I would recommend quickly assessing whether there is any impact outside RelatedArticles before applying the fix and making this public.

We'd plan to deploy this as a security patch to Wikimedia production. We'd want to hold off on making it public in gerrit until the next supplemental security release.

Jun 11 2025, 1:26 PM · Web-Team, RelatedArticles, affects-Miraheze, Vuln-XSS, Security, Security-Team

Jun 9 2025

RhinosF1 added a comment to T394708: Security issue access for Paladox.

Thanks all!

Jun 9 2025, 4:19 PM · SecTeam-Processed, Security, Security-Team, affects-Miraheze

Jun 5 2025

RhinosF1 added a comment to T395934: NEW BUG REPORT: Investigate rise in May 2025 Reader metrics.

Slightly note of an interest, I saw a very similar pattern recently for Miraheze in our Cloudflare data so possible this affects for than the WMF. I can pull actual data later.

Jun 5 2025, 6:14 AM · Movement-Insights (FY25-26 H1), Data-Engineering (Q1 FY25/26 July 1st - September 30th), Traffic

May 29 2025

RhinosF1 updated subscribers of T394708: Security issue access for Paladox.

@KFrancis: can you start that?

May 29 2025, 4:07 PM · SecTeam-Processed, Security, Security-Team, affects-Miraheze

May 27 2025

RhinosF1 added a comment to T394938: CVE-2025-53494: Stored XSS through a system message in TwoColConflict.

I removed it because it needed to be brought to security team's attention again because somehow the report in _security & via email was completely missed.

It's not for you to remove. Please do not do it again. There are other ways of contacting the Security-Team, as you've mentioned above. Both of which did receive replies as you have incorrectly noted here. Two on-call WMF staff members both correctly described this issue as low risk and not an immediate worry in #mediawiki_security, responding to @Urbanecm's message. That answer should absolutely have sufficed. I also replied to your email this morning and noted that the security team would be getting to these issues today during our clinic, which was delayed due to a Monday US holiday and an ongoing Wikimedia production incident. The Security-Team does not have unlimited resources nor do we guarantee 24/7 on-call services for every possible security-related issue.

There is still a process to follow though that security team are supposed to manage for WMF Deployed code. If this was a third party extension, we'd normally wait on task for your triage and for you to determine whether it's safe to be made public via a gerrit patch (and normally ensure that patch gets a speedy review). For a WMF Deployed Security issue, you guys are supposed to help us manage the private patch and deployment process to ensure WMF wikis are patched before the issue is exposed and normally would then release yourselves at security release time. This task has gone against the norm for reasons I'm not certain of but the lack of engagement is again embarrassing.

Processes are great when they are followed. That wasn't the case here and not due to the actions of anyone on the Security-Team. When incidents like this happen, people have to take out-of-process actions to correct the matter, which doesn't always happen perfectly and instantly.

As far as I can tell, _security was ignored. My email wasn't read. The patch was +2'd despite already being merged. This isn't an effective security release and someone needs to explain why again we're chasing the basics.

Most of this is incorrect as I mentioned above. I gave a quick +2 because from the comments on this task, it seemed like the patch hadn't been merged yet, nor cut for 1.45.0-wmf.3, both of which were incorrect. You're free to form your own opinions but I would advise not doing so on false assumptions and misinformation.

May 27 2025, 5:14 PM · SecTeam-Processed, WMDE-TechWish-Sprint-2025-05-14, Two-Column-Edit-Conflict-Merge, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 added a comment to T394938: CVE-2025-53494: Stored XSS through a system message in TwoColConflict.

Please don't remove SecTeam-Processed. That's an internal tag for the Security-Team's tracking.

I removed it because it needed to be brought to security team's attention again because somehow the report in _security & via email was completely missed.

This is already on 1.45.0-wmf.3, so at this point it just needs to ride the train the rest of the week to land in Wikimedia production. For most of these message XSS issues, we've traditionally considered them low risk since you'd need to compromise the MediaWiki message as well, which is non-trivial for unprivileged users.

Once a patch is up in gerrit, it can be backported by pretty much anyone. I can get those started now for supported release versions.

There is still a process to follow though that security team are supposed to manage for WMF Deployed code. If this was a third party extension, we'd normally wait on task for your triage and for you to determine whether it's safe to be made public via a gerrit patch (and normally ensure that patch gets a speedy review). For a WMF Deployed Security issue, you guys are supposed to help us manage the private patch and deployment process to ensure WMF wikis are patched before the issue is exposed and normally would then release yourselves at security release time. This task has gone against the norm for reasons I'm not certain of but the lack of engagement is again embarrassing.

May 27 2025, 4:36 PM · SecTeam-Processed, WMDE-TechWish-Sprint-2025-05-14, Two-Column-Edit-Conflict-Merge, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 removed a project from T394938: CVE-2025-53494: Stored XSS through a system message in TwoColConflict: SecTeam-Processed.
May 27 2025, 4:03 PM · SecTeam-Processed, WMDE-TechWish-Sprint-2025-05-14, Two-Column-Edit-Conflict-Merge, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 updated subscribers of T394938: CVE-2025-53494: Stored XSS through a system message in TwoColConflict.

Untagging Security-Team as it looks like WMDE plans to review this? Since this extension is Wikimedia-production-deployed, please code-review on this task and do not push the patch to gerrit. Once reviewed, the Security-Team can assist with a Wikimedia production deployment.

A bit late for that one. As per my email to security-help and flag by @Urbanecm in _security on IRC, this has been public for 48 hours on gerrit and afaik not deployed to production.

May 27 2025, 4:02 PM · SecTeam-Processed, WMDE-TechWish-Sprint-2025-05-14, Two-Column-Edit-Conflict-Merge, affects-Miraheze, Vuln-XSS, Security, Security-Team

May 25 2025

RhinosF1 added a comment to T395201: Quarry down - web service unreachable.

04:32:28 <wmcs-alerts> FIRING: [2x] TargetDown: Job app is unreachable in project quarry instance quarry.wmcloud.org:443  - https://prometheus-alerts.wmcloud.org/?q=alertname%3DTargetDown
04:32:39 <wmcs-alerts> FIRING: QuarryDown: Quarry application is unreachable  - https://prometheus-alerts.wmcloud.org/?q=alertname%3DQuarryDown

May 25 2025, 7:11 AM · Quarry
RhinosF1 renamed T395201: Quarry down - web service unreachable from Is Quarry down? to Quarry down - web service unreachable.
May 25 2025, 7:09 AM · Quarry

May 22 2025

RhinosF1 updated subscribers of T394721: CVE-2025-7363: XSS in TitleIcon.

Please also do a version bump to 6.2.1 in extension.json in all patched branches that did not get a MW version bump and a version bump to 6.3.0 in all branches that got a MW version bump from 1.39.0 to 1.40.0. Thank you!

Hi Cindy, I don't think that's a normal part of the security patching process. If you want to follow up with a version bump, you're more than welcome to.

May 22 2025, 7:47 PM · SecTeam-Processed, Vuln-XSS, MediaWiki-extensions-Title-Icon, affects-Miraheze, Security, Security-Team

May 19 2025

RhinosF1 added a comment to T394708: Security issue access for Paladox.

I followed https://wikitech.wikimedia.org/wiki/Volunteer_NDA because you need an NDA as part of getting security issue access

May 19 2025, 6:25 PM · SecTeam-Processed, Security, Security-Team, affects-Miraheze
RhinosF1 created T394708: Security issue access for Paladox.
May 19 2025, 5:14 PM · SecTeam-Processed, Security, Security-Team, affects-Miraheze
RhinosF1 added a comment to T394383: CVE-2025-53487: Stored XSS through system messages in Extension:ApprovedRevs.

Similar to my comment in T394612#10835735, the above patch should likely be pushed through gerrit since it isn't Wikimedia-deployed. Unless Miraheze would like to hold the patch until they've patched their production environments.

We're looking at this now, I also PM'd you on IRC a question.

May 19 2025, 4:56 PM · MediaWiki-extensions-Approved-Revs, Patch-For-Review, Vuln-XSS, SecTeam-Processed, affects-Miraheze, Security
RhinosF1 updated subscribers of T394612: CVE-2025-7057: Stored XSS through a system message in Extension:Quiz.
May 19 2025, 4:46 PM · Security-Team, SecTeam-Processed, MediaWiki-extensions-Quiz, Vuln-XSS, affects-Miraheze, Security
RhinosF1 updated subscribers of T394383: CVE-2025-53487: Stored XSS through system messages in Extension:ApprovedRevs.
May 19 2025, 4:46 PM · MediaWiki-extensions-Approved-Revs, Patch-For-Review, Vuln-XSS, SecTeam-Processed, affects-Miraheze, Security

May 7 2025

RhinosF1 updated the task description for T390914: Upgrade cloud-vps openstack to version 'Epoxy'.
May 7 2025, 7:46 PM · cloud-services-team, Cloud-VPS

May 5 2025

RhinosF1 added a member for Wikimedia-Incident: RhinosF1.
May 5 2025, 10:03 AM

May 1 2025

RhinosF1 added projects to T393092: Confusion over which interface sets ssh keys for use with Gerrit (hint: not IDM): collaboration-services, Release-Engineering-Team.
May 1 2025, 11:18 AM · Essential-Work, Release-Engineering-Team (Doing 😎), collaboration-services, Bitu, Infrastructure-Foundations, Gerrit

Apr 30 2025

RhinosF1 added a member for Trusted-Contributors: OriginalAuthority.
Apr 30 2025, 6:05 AM

Apr 29 2025

RhinosF1 added a member for Trusted-Contributors: SomeRandomDeveloper.
Apr 29 2025, 5:21 PM

Apr 26 2025

RhinosF1 added a comment to T392746: CVE-2025-6590: Complete content leak of private wikis due to PasswordReset Wikitext injection in error message.

Does anyone have a problem if I deploy this patch to Miraheze too?

No problems with you all deploying, but please be extremely careful to avoid public disclosure of the issue and the patch at this time.

Apr 26 2025, 1:37 PM · MW-1.39-release, MW-1.42-release, MW-1.43-release, MW-1.44-notes, SecTeam-Processed, MediaWiki-User-login-and-signup, MediaWiki-HTMLForm, Vuln-Infoleak, Security, Security-Team
RhinosF1 added a comment to T392746: CVE-2025-6590: Complete content leak of private wikis due to PasswordReset Wikitext injection in error message.

Apr 26 2025, 7:58 AM · MW-1.39-release, MW-1.42-release, MW-1.43-release, MW-1.44-notes, SecTeam-Processed, MediaWiki-User-login-and-signup, MediaWiki-HTMLForm, Vuln-Infoleak, Security, Security-Team

Apr 21 2025

RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Apr 21 2025, 5:30 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

@sbassett: Thanks for adding the template. CVE is pending review and we'll issue through GitHub's CNA.

Apr 21 2025, 5:26 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Apr 21 2025, 5:25 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Apr 20 2025

RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

https://github.com/miraheze/ManageWiki/security/advisories/GHSA-gg42-cv66-f5x7 should probably be included

Apr 20 2025, 7:40 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Apr 15 2025

RhinosF1 added a comment to T388996: Move CampaignEvents maintenance scripts to job queue.

Feel free to email or ping me on IRC

Apr 15 2025, 3:11 PM · Connection-Team, affects-Miraheze, CampaignEvents

Apr 14 2025

RhinosF1 added a comment to T54465: VisualEditor plus Parsoid without using https can break security when using external Parsoid calls (i.e. not using localhost:port Parsoid).

@cscott @ssastry - Per Roan's explanation in T54465#545525, I'm assuming this wasn't a very concerning issue to begin with, and is very likely irrelevant now? Unless an external operator does something extremely dangerous with their own config? If so, I'd love to decline this 11-year-old task.

@cscott: ping again as you had no view permissions before.

Apr 14 2025, 4:04 PM · SecTeam-Processed, Security, VisualEditor, RESTBase
RhinosF1 changed the visibility for T54465: VisualEditor plus Parsoid without using https can break security when using external Parsoid calls (i.e. not using localhost:port Parsoid).
Apr 14 2025, 4:03 PM · SecTeam-Processed, Security, VisualEditor, RESTBase

Apr 13 2025

RhinosF1 added a comment to T391750: QuickInstantCommons does not use the title capitalization of the file repo.

Given that this affects Miraheze and that Miraheze runs 1.43, I assume this should also be backported to the REL1_43 branch for it to take effect there? I'm not 100% sure about how Miraheze deploys extension updates and backports, so some clarity would be appreciated here.

Apr 13 2025, 4:15 PM · affects-Miraheze, MediaWiki-extensions-QuickInstantCommons

Apr 12 2025

RhinosF1 closed T388996: Move CampaignEvents maintenance scripts to job queue as Invalid.

This wasn't needed for us anyway and we're probably not deploying the extension anyway. Closing.

Apr 12 2025, 8:02 PM · Connection-Team, affects-Miraheze, CampaignEvents
RhinosF1 added a project to T391750: QuickInstantCommons does not use the title capitalization of the file repo: affects-Miraheze.

Report originated from one of our wikis

Apr 12 2025, 7:59 PM · affects-Miraheze, MediaWiki-extensions-QuickInstantCommons

Apr 11 2025

RhinosF1 added a comment to T382326: Write and send supplementary release announcement for extensions and skins with security patches (1.39.12/1.42.6/1.43.1).

Given the entire email was the wrong version, I'd say it's probably a good idea to send out the correct supplement, yes.

Ugh, well, I just sent out a correction because I assumed the email content was at least correct :/

Nope, you'll notice in the email all the CVEs are CVE-2024-XXXX

Apr 11 2025, 8:42 PM · user-sbassett, MediaWiki-Releasing, Security
RhinosF1 added a comment to T382326: Write and send supplementary release announcement for extensions and skins with security patches (1.39.12/1.42.6/1.43.1).

Given the entire email was the wrong version, I'd say it's probably a good idea to send out the correct supplement, yes.

Apr 11 2025, 8:37 PM · user-sbassett, MediaWiki-Releasing, Security
RhinosF1 reopened T382326: Write and send supplementary release announcement for extensions and skins with security patches (1.39.12/1.42.6/1.43.1) as "Open".

Email linked and sent is

MediaWiki Extensions and Skins Security Release Supplement (1.39.9/1.41.3/1.42.2)

NOT

Subject: MediaWiki Extensions and Skins Security Release Supplement (1.39.12/1.42.6/1.43.1)

Apr 11 2025, 5:35 PM · user-sbassett, MediaWiki-Releasing, Security

Apr 1 2025

RhinosF1 closed T390593: wikistats - import miraheze timer/service failed as Resolved.
Apr 1 2025, 6:57 AM · VPS-project-Wikistats, affects-Miraheze
RhinosF1 added a comment to T390593: wikistats - import miraheze timer/service failed.

Thank you! The service runs again.

regarding the API change: Maybe it could be reconsidered if renaming siteprop to prop (not sure it says why) is worth breaking it for all users of the API.

Apr 1 2025, 6:56 AM · VPS-project-Wikistats, affects-Miraheze

Mar 16 2025

RhinosF1 added a comment to T387861: Remove SUL3 opt-in code from CentralAuth.

The third isn't of interested to me, we can change all wikis at once. I'd just like us to be able to plan it properly. The second kind of is because I'd love to use the SUL3 opportunity to get rid of the historical abomination that is using loginwiki for GlobalUserPage

Mar 16 2025, 8:46 PM · MW-1.44-notes (1.44.0-wmf.27; 2025-04-29), affects-Miraheze, MediaWiki-Platform-Team, MediaWiki-extensions-CentralAuth, SUL3

Mar 11 2025

RhinosF1 added a member for Trusted-Contributors: Aeyeu.
Mar 11 2025, 7:48 AM

Mar 10 2025

RhinosF1 added projects to T388359: SimpleBlogPage breaks with BlueSpice function requirements: BlueSpice, Gerrit.
Mar 10 2025, 6:46 AM · BlueSpice, affects-Miraheze

Mar 6 2025

RhinosF1 added a project to T387861: Remove SUL3 opt-in code from CentralAuth: affects-Miraheze.

Maybe we want to keep isSul3Enabled() and simplify it to a simple per-wiki yes/no flag, for third-party wikis, but I'm not sure we want to do even that much, rather than just assuming SUL3 is always enabled. Although we have to keep in it at least a few places in the code for at least a year because of API backwards compatibility (e.g. T364829: Update Wikimedia apps to use central login domain).

Mar 6 2025, 7:24 PM · MW-1.44-notes (1.44.0-wmf.27; 2025-04-29), affects-Miraheze, MediaWiki-Platform-Team, MediaWiki-extensions-CentralAuth, SUL3
RhinosF1 added a member for SUL3: RhinosF1.
Mar 6 2025, 7:21 PM

Mar 2 2025

RhinosF1 closed T387672: Template Rendering Issue as Invalid.

This is a content error and poses no security risk.

Mar 2 2025, 7:28 PM · SecTeam-Processed

Feb 27 2025

RhinosF1 added a watcher for Vulnerability Management: RhinosF1.
Feb 27 2025, 6:19 PM

Feb 13 2025

RhinosF1 updated subscribers of T386382: Phabricator Bot request for WMDE GitHub notifications.
Feb 13 2025, 4:29 PM · Release-Engineering-Team (Priority Backlog 📥), Phabricator-Bot-Requests
RhinosF1 added a project to T386382: Phabricator Bot request for WMDE GitHub notifications: Phabricator maintenance bot.

I think @Maintenance_bot will automatically remove the Patch for Review tag in this case.

Feb 13 2025, 4:28 PM · Release-Engineering-Team (Priority Backlog 📥), Phabricator-Bot-Requests

Feb 6 2025

RhinosF1 added a comment to T385803: deployment-prep is broken following 2025-02-06 WMCS reboots.

15:31:32 <wmf-insecte> Yippee, build fixed!
15:31:33 <wmf-insecte> Project beta-update-databases-eqiad build #82385: FIXED in 11 min: https://integration.wikimedia.org/ci/job/beta-update-databases-eqiad/82385/

Feb 6 2025, 3:33 PM · User-bd808, Beta-Cluster-Infrastructure
RhinosF1 updated the task description for T385803: deployment-prep is broken following 2025-02-06 WMCS reboots.
Feb 6 2025, 3:16 PM · User-bd808, Beta-Cluster-Infrastructure
RhinosF1 added a comment to T385803: deployment-prep is broken following 2025-02-06 WMCS reboots.

15:14:33 <@andrewbogott> RhinosF1: ok, I can't arm keyholder on that host with the scap password or the deploy-service password or the mwdeploy password

Feb 6 2025, 3:15 PM · User-bd808, Beta-Cluster-Infrastructure
RhinosF1 triaged T385803: deployment-prep is broken following 2025-02-06 WMCS reboots as High priority.
Feb 6 2025, 2:42 PM · User-bd808, Beta-Cluster-Infrastructure
RhinosF1 created T385803: deployment-prep is broken following 2025-02-06 WMCS reboots.
Feb 6 2025, 2:42 PM · User-bd808, Beta-Cluster-Infrastructure

Jan 31 2025

RhinosF1 added a project to T385222: Support TLS 1.3: affects-Miraheze.
Jan 31 2025, 6:31 AM · affects-Miraheze, AutoWikiBrowser-Priorities

Jan 30 2025

RhinosF1 added a project to T385223: Make AWB use newer .NET version?: affects-Miraheze.
Jan 30 2025, 7:54 PM · affects-Miraheze, AutoWikiBrowser-Priorities