Shawn O. Pearce | d2cacd1 | 2012-06-21 16:28:58 -0700 | [diff] [blame] | 1 | Release notes for Gerrit 2.4.2 |
| 2 | ============================== |
| 3 | |
| 4 | Gerrit 2.4.2 is now available: |
| 5 | |
| 6 | link:http://code.google.com/p/gerrit/downloads/detail?name=gerrit-2.4.2.war[http://code.google.com/p/gerrit/downloads/detail?name=gerrit-2.4.2.war] |
| 7 | |
| 8 | There are no schema changes from 2.4, or 2.4.1. |
| 9 | |
| 10 | However, if upgrading from anything earlier, follow the upgrade |
| 11 | procedure in the 2.4 link:ReleaseNotes-2.4.html[ReleaseNotes]. |
| 12 | |
| 13 | Security Fixes |
| 14 | -------------- |
| 15 | * Some access control sections may be ignored |
| 16 | + |
| 17 | Gerrit sometimes ignored an access control section in a project |
| 18 | if the exact same section name appeared in All-Projects. The bug |
| 19 | required an unrelated project to have access.inheritFrom set to |
| 20 | All-Projects and be accessed before the project that has the same |
| 21 | section name as All-Projects. This is an unlikely scenario for |
| 22 | most servers, as Gerrit does not normally set inheritFrom equal to |
| 23 | All-Projects. The usual behavior is to not supply this property in |
David Pursehouse | 4d7ac77 | 2013-06-25 17:14:30 +0900 | [diff] [blame] | 24 | project.config, and permit the implicit inheritance to take place. |