contrib: drop hg-to-git script

The hg-to-git script is full of command injection vulnerabilities against malicious branch and tag names. It's also old and largely unmaintained; the last commit was over 4 years ago, and the last code change before that was from 2013. Users are better off with a modern remote-helper tool like cinnabar or remote-hg. So rather than spending time to fix it, let's just get rid of it. Reported-by: Matthew Rollings <admin@stealthcopter.com> Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Jeff King committed Mar 20, 2024 at 05:48 UTC ba155b5cb7cdad1c2cdaf5aa9ff01adb4226aa3f
2 files changed -275
contrib/hg-to-git/hg-to-git.py deleted
-254
@@ -1,254 +0,0 @@
1 -#!/usr/bin/env python
2 -
3 -""" hg-to-git.py - A Mercurial to GIT converter
4 -
5 - Copyright (C)2007 Stelian Pop <stelian@popies.net>
6 -
7 - This program is free software; you can redistribute it and/or modify
8 - it under the terms of the GNU General Public License as published by
9 - the Free Software Foundation; either version 2, or (at your option)
10 - any later version.
11 -
12 - This program is distributed in the hope that it will be useful,
13 - but WITHOUT ANY WARRANTY; without even the implied warranty of
14 - MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 - GNU General Public License for more details.
16 -
17 - You should have received a copy of the GNU General Public License
18 - along with this program; if not, see <http://www.gnu.org/licenses/>.
19 -"""
20 -
21 -import os, os.path, sys
22 -import tempfile, pickle, getopt
23 -import re
24 -
25 -if sys.hexversion < 0x02030000:
26 - # The behavior of the pickle module changed significantly in 2.3
27 - sys.stderr.write("hg-to-git.py: requires Python 2.3 or later.\n")
28 - sys.exit(1)
29 -
30 -# Maps hg version -> git version
31 -hgvers = {}
32 -# List of children for each hg revision
33 -hgchildren = {}
34 -# List of parents for each hg revision
35 -hgparents = {}
36 -# Current branch for each hg revision
37 -hgbranch = {}
38 -# Number of new changesets converted from hg
39 -hgnewcsets = 0
40 -
41 -#------------------------------------------------------------------------------
42 -
43 -def usage():
44 -
45 - print("""\
46 -%s: [OPTIONS] <hgprj>
47 -
48 -options:
49 - -s, --gitstate=FILE: name of the state to be saved/read
50 - for incrementals
51 - -n, --nrepack=INT: number of changesets that will trigger
52 - a repack (default=0, -1 to deactivate)
53 - -v, --verbose: be verbose
54 -
55 -required:
56 - hgprj: name of the HG project to import (directory)
57 -""" % sys.argv[0])
58 -
59 -#------------------------------------------------------------------------------
60 -
61 -def getgitenv(user, date):
62 - env = ''
63 - elems = re.compile('(.*?)\s+<(.*)>').match(user)
64 - if elems:
65 - env += 'export GIT_AUTHOR_NAME="%s" ;' % elems.group(1)
66 - env += 'export GIT_COMMITTER_NAME="%s" ;' % elems.group(1)
67 - env += 'export GIT_AUTHOR_EMAIL="%s" ;' % elems.group(2)
68 - env += 'export GIT_COMMITTER_EMAIL="%s" ;' % elems.group(2)
69 - else:
70 - env += 'export GIT_AUTHOR_NAME="%s" ;' % user
71 - env += 'export GIT_COMMITTER_NAME="%s" ;' % user
72 - env += 'export GIT_AUTHOR_EMAIL= ;'
73 - env += 'export GIT_COMMITTER_EMAIL= ;'
74 -
75 - env += 'export GIT_AUTHOR_DATE="%s" ;' % date
76 - env += 'export GIT_COMMITTER_DATE="%s" ;' % date
77 - return env
78 -
79 -#------------------------------------------------------------------------------
80 -
81 -state = ''
82 -opt_nrepack = 0
83 -verbose = False
84 -
85 -try:
86 - opts, args = getopt.getopt(sys.argv[1:], 's:t:n:v', ['gitstate=', 'tempdir=', 'nrepack=', 'verbose'])
87 - for o, a in opts:
88 - if o in ('-s', '--gitstate'):
89 - state = a
90 - state = os.path.abspath(state)
91 - if o in ('-n', '--nrepack'):
92 - opt_nrepack = int(a)
93 - if o in ('-v', '--verbose'):
94 - verbose = True
95 - if len(args) != 1:
96 - raise Exception('params')
97 -except:
98 - usage()
99 - sys.exit(1)
100 -
101 -hgprj = args[0]
102 -os.chdir(hgprj)
103 -
104 -if state:
105 - if os.path.exists(state):
106 - if verbose:
107 - print('State does exist, reading')
108 - f = open(state, 'r')
109 - hgvers = pickle.load(f)
110 - else:
111 - print('State does not exist, first run')
112 -
113 -sock = os.popen('hg tip --template "{rev}"')
114 -tip = sock.read()
115 -if sock.close():
116 - sys.exit(1)
117 -if verbose:
118 - print('tip is', tip)
119 -
120 -# Calculate the branches
121 -if verbose:
122 - print('analysing the branches...')
123 -hgchildren["0"] = ()
124 -hgparents["0"] = (None, None)
125 -hgbranch["0"] = "master"
126 -for cset in range(1, int(tip) + 1):
127 - hgchildren[str(cset)] = ()
128 - prnts = os.popen('hg log -r %d --template "{parents}"' % cset).read().strip().split(' ')
129 - prnts = map(lambda x: x[:x.find(':')], prnts)
130 - if prnts[0] != '':
131 - parent = prnts[0].strip()
132 - else:
133 - parent = str(cset - 1)
134 - hgchildren[parent] += ( str(cset), )
135 - if len(prnts) > 1:
136 - mparent = prnts[1].strip()
137 - hgchildren[mparent] += ( str(cset), )
138 - else:
139 - mparent = None
140 -
141 - hgparents[str(cset)] = (parent, mparent)
142 -
143 - if mparent:
144 - # For merge changesets, take either one, preferably the 'master' branch
145 - if hgbranch[mparent] == 'master':
146 - hgbranch[str(cset)] = 'master'
147 - else:
148 - hgbranch[str(cset)] = hgbranch[parent]
149 - else:
150 - # Normal changesets
151 - # For first children, take the parent branch, for the others create a new branch
152 - if hgchildren[parent][0] == str(cset):
153 - hgbranch[str(cset)] = hgbranch[parent]
154 - else:
155 - hgbranch[str(cset)] = "branch-" + str(cset)
156 -
157 -if "0" not in hgvers:
158 - print('creating repository')
159 - os.system('git init')
160 -
161 -# loop through every hg changeset
162 -for cset in range(int(tip) + 1):
163 -
164 - # incremental, already seen
165 - if str(cset) in hgvers:
166 - continue
167 - hgnewcsets += 1
168 -
169 - # get info
170 - log_data = os.popen('hg log -r %d --template "{tags}\n{date|date}\n{author}\n"' % cset).readlines()
171 - tag = log_data[0].strip()
172 - date = log_data[1].strip()
173 - user = log_data[2].strip()
174 - parent = hgparents[str(cset)][0]
175 - mparent = hgparents[str(cset)][1]
176 -
177 - #get comment
178 - (fdcomment, filecomment) = tempfile.mkstemp()
179 - csetcomment = os.popen('hg log -r %d --template "{desc}"' % cset).read().strip()
180 - os.write(fdcomment, csetcomment)
181 - os.close(fdcomment)
182 -
183 - print('-----------------------------------------')
184 - print('cset:', cset)
185 - print('branch:', hgbranch[str(cset)])
186 - print('user:', user)
187 - print('date:', date)
188 - print('comment:', csetcomment)
189 - if parent:
190 - print('parent:', parent)
191 - if mparent:
192 - print('mparent:', mparent)
193 - if tag:
194 - print('tag:', tag)
195 - print('-----------------------------------------')
196 -
197 - # checkout the parent if necessary
198 - if cset != 0:
199 - if hgbranch[str(cset)] == "branch-" + str(cset):
200 - print('creating new branch', hgbranch[str(cset)])
201 - os.system('git checkout -b %s %s' % (hgbranch[str(cset)], hgvers[parent]))
202 - else:
203 - print('checking out branch', hgbranch[str(cset)])
204 - os.system('git checkout %s' % hgbranch[str(cset)])
205 -
206 - # merge
207 - if mparent:
208 - if hgbranch[parent] == hgbranch[str(cset)]:
209 - otherbranch = hgbranch[mparent]
210 - else:
211 - otherbranch = hgbranch[parent]
212 - print('merging', otherbranch, 'into', hgbranch[str(cset)])
213 - os.system(getgitenv(user, date) + 'git merge --no-commit -s ours "" %s %s' % (hgbranch[str(cset)], otherbranch))
214 -
215 - # remove everything except .git and .hg directories
216 - os.system('find . \( -path "./.hg" -o -path "./.git" \) -prune -o ! -name "." -print | xargs rm -rf')
217 -
218 - # repopulate with checkouted files
219 - os.system('hg update -C %d' % cset)
220 -
221 - # add new files
222 - os.system('git ls-files -x .hg --others | git update-index --add --stdin')
223 - # delete removed files
224 - os.system('git ls-files -x .hg --deleted | git update-index --remove --stdin')
225 -
226 - # commit
227 - os.system(getgitenv(user, date) + 'git commit --allow-empty --allow-empty-message -a -F %s' % filecomment)
228 - os.unlink(filecomment)
229 -
230 - # tag
231 - if tag and tag != 'tip':
232 - os.system(getgitenv(user, date) + 'git tag %s' % tag)
233 -
234 - # delete branch if not used anymore...
235 - if mparent and len(hgchildren[str(cset)]):
236 - print("Deleting unused branch:", otherbranch)
237 - os.system('git branch -d %s' % otherbranch)
238 -
239 - # retrieve and record the version
240 - vvv = os.popen('git show --quiet --pretty=format:%H').read()
241 - print('record', cset, '->', vvv)
242 - hgvers[str(cset)] = vvv
243 -
244 -if hgnewcsets >= opt_nrepack and opt_nrepack != -1:
245 - os.system('git repack -a -d')
246 -
247 -# write the state for incrementals
248 -if state:
249 - if verbose:
250 - print('Writing state')
251 - f = open(state, 'w')
252 - pickle.dump(hgvers, f)
253 -
254 -# vim: et ts=8 sw=4 sts=4
contrib/hg-to-git/hg-to-git.txt deleted
-21
@@ -1,21 +0,0 @@
1 -hg-to-git.py is able to convert a Mercurial repository into a git one,
2 -and preserves the branches in the process (unlike tailor)
3 -
4 -hg-to-git.py can probably be greatly improved (it's a rather crude
5 -combination of shell and python) but it does already work quite well for
6 -me. Features:
7 - - supports incremental conversion
8 - (for keeping a git repo in sync with a hg one)
9 - - supports hg branches
10 - - converts hg tags
11 -
12 -Note that the git repository will be created 'in place' (at the same
13 -location as the source hg repo). You will have to manually remove the
14 -'.hg' directory after the conversion.
15 -
16 -Also note that the incremental conversion uses 'simple' hg changesets
17 -identifiers (ordinals, as opposed to SHA-1 ids), and since these ids
18 -are not stable across different repositories the hg-to-git.py state file
19 -is forever tied to one hg repository.
20 -
21 -Stelian Pop <stelian@popies.net>