Restrict shell commands by default
[lhc/web/wiklou.git] / RELEASE-NOTES-1.31
1 == MediaWiki 1.31 ==
2
3 THIS IS NOT A RELEASE YET
4
5 MediaWiki 1.31 is an alpha-quality branch and is not recommended for use in
6 production.
7
8 === Configuration changes in 1.31 ===
9 * $wgEnableAPI and $wgEnableWriteAPI are now deprecated and will be removed in
10 a future version. The API is now considered to be stable, secure and
11 essential.
12 * $wgUsejQueryThree was removed, as it is now the default. This was documented as a
13 temporary variable during the migration period, deprecated since 1.29.
14 * $wgLogoHD has been updated to support svg images and uses $wgLogo where
15 possible for fallback images such as png.
16 * (T44246) $wgFilterLogTypes will no longer ignore 'patrol' when user does
17 not have the right to mark things patrolled.
18 * Wikis that contain imported revisions or CentralAuth global blocks should run
19 maintenance/cleanupUsersWithNoId.php.
20 * $wgResourceLoaderMinifierStatementsOnOwnLine and $wgResourceLoaderMinifierMaxLineLength
21 were removed (deprecated since 1.27).
22 * (T180921) $wgReferrerPolicy now supports having fallbacks for browsers that are not
23 using the latest version of the Referrer Policy specification.
24 * $wgFragmentMode is now set to [ 'legacy', 'html5' ] by default. This is a first step of
25 migration to human-readable section IDs that will later result in 'html5' being the
26 default mode.
27 * CACHE_ACCEL now only supports APC(u) or WinCache. XCache support was removed
28 as upstream is inactive and has no plans to move to PHP 7.
29 * The old CategorizedRecentChanges feature, including its related configuration
30 option $wgAllowCategorizedRecentChanges, has been removed.
31 * (T188472) The 'comma' value for $wgArticleCountMethod is no longer supported for
32 performance reasons, and installations with this setting will now work as if it
33 was configured with 'any'.
34 * (T185753) MediaWiki now defaults to using RemexHtml to tidy up user input, rather than
35 being off by default. If you wish to disable HTML tidying entirely, set $wgTidyConfig
36 to null; if you wish to use the old, deprecated Tidy external binary, both
37 set $wgTidyConfig to null and also set $wgUseTidy to true.
38 * $wgLogAutopatrol now defaults to false instead of true.
39 * $wgValidateAllHtml was removed and will be ignored.
40
41 === New features in 1.31 ===
42 * (T76554) User sub-pages named ….json are now protected in the same way that ….js
43 and ….css pages are, so that configuration options can safely be placed there.
44 * Wikimedia\Rdbms\IDatabase->select() and similar methods now support
45 joins with parentheses for grouping.
46 * As a first pass in standardizing dialog boxes across the MediaWiki product,
47 Html class now provides helper methods for messageBox, successBox, errorBox and
48 warningBox generation.
49 * (T9240) Imports will now record unknown (and, optionally, known) usernames in
50 a format like "iw>Example".
51 * (T20209) Linker (used on history pages, log pages, and so on) will display
52 usernames formed like "iw>Example" as interwiki links, as if by wikitext like
53 [[iw:User:Example|iw>Example]].
54 * (T111605) The 'ImportHandleUnknownUser' hook allows extensions to auto-create
55 users during an import.
56 * Added a hook, ParserOutputPostCacheTransform, to allow extensions to affect
57 the ParserOutput::getText() post-cache transformations.
58 * Added a hook, UploadForm:getInitialPageText, to allow extensions to alter the
59 initial page text for file uploads.
60 * (T181651) The info page for File pages now displays the file's base-16 SHA1
61 hash value in the table of basic information.
62 * Style tags with a 'data-mw-deduplicate' attribute will be deduplicated as a
63 ParserOutput::getText() post-cache transformation. This may be disabled by
64 passing 'deduplicateStyles' => false to that method.
65 * The identity of the logged-in or IP "actor" for logged actions is being moved
66 into a new actor table, with the rows in tables such as revision and logging
67 referring to the actor ID instead of storing the user ID and name/IP in
68 every row.
69 * This is currently gated by $wgActorTableSchemaMigrationStage. Most wikis
70 can set this to MIGRATION_NEW and run maintenance/migrateActors.php as
71 soon as any necessary extensions are updated.
72 * Most code accessing rows for logged actions from the database should use
73 the relevant getQueryInfo() methods to get the information needed to build
74 the SQL query. The ActorMigration class may also be used to get feature-flagged
75 information needed to access actor-related fields during the migration
76 period.
77 * Added Wikimedia\Rdbms\IDatabase::cancelAtomic(), to roll back an atomic
78 section without having to roll back the whole transaction.
79 * Wikimedia\Rdbms\IDatabase::doAtomicSection(), non-native ::insertSelect(),
80 and non-MySQL ::replace() and ::upsert() no longer roll back the whole
81 transaction on failure.
82 * (T189785) Added a monthly heartbeat ping to the pingback feature.
83 * The CLI installer (maintenance/install.php) learned to detect and include
84 extensions. Pass --with-extensions to enable that feature.
85 * (T184791) rc_patrolled now has three states: "0" for unpatrolled,
86 "1" for manually patrolled and "2" for autopatrolled actions.
87 * Extensions can now set their type to "editor" if they provide an editor
88 or enhance the editing experience.
89 * Extensions can use a PSR-4 autoloader by setting an "AutoloadNamespaces" property
90 in extension.json. See
91 <https://www.mediawiki.org/wiki/Manual:Extension.json/Schema#AutoloadNamespaces>
92 for more details and an example.
93
94 === External library changes in 1.31 ===
95
96 ==== Upgraded external libraries ====
97 * Updated jquery.chosen from v0.9.14 to v1.8.2.
98 * Updated composer/spdx-licenses from 1.1.4 to
99 1.3.0 (development dependency).
100 * Updated nikic/php-parser from 2.1.0 to 3.1.3
101 (development dependency).
102 * Updated wikimedia/ip-set from 1.1.0 to 1.2.0.
103 * Updated wikimedia/relpath from 2.0.0 to 2.1.1.
104 * Updated wikimedia/running-stat from 1.1.0 to 1.2.0.
105 * Updated wikimedia/wrappedstring from 2.2.0 to 2.3.0.
106 * Updated mediawiki/at-ease from 1.1.0 to 1.2.0.
107 * Updated wikimedia/php-session-serializer from 1.0.4 to 1.0.5.
108 * Updated wikimedia/remex-html from 1.0.2 to 1.0.3.
109 * …
110
111 ==== New external libraries ====
112 * Added wikimedia/object-factory 1.0.0
113 * …
114
115 ==== Removed and replaced external libraries ====
116 * (T17845) The deprecated 'jquery.badge' module was removed.
117 * The deprecated 'jquery.autoEllipsis' module was removed. Use the CSS
118 text-overflow property instead.
119 * The deprecated 'jquery.placeholder' module was removed.
120 * The deprecated 'jquery.appear' module was removed. Use the
121 'mediawiki.viewport' module instead.
122 * The deprecated 'mediawiki.widgets.CategorySelector' module alias was removed.
123 Use the 'mediawiki.widgets.CategoryMultiselectWidget' module directly instead.
124
125 === Bug fixes in 1.31 ===
126 * (T90902) Non-breaking space in header ID breaks anchor
127
128 === Action API changes in 1.31 ===
129 * (T185058) The 'name' value to tgprop for action=query&list=tags has been
130 removed. It has never made a difference in the output, the name was always
131 returned regardless.
132
133 === Action API internal changes in 1.31 ===
134 * ApiBase::getProfileDBTime was removed (deprecated since 1.25)
135 * ApiBase::getModuleProfileName was removed (deprecated since 1.25)
136 * ApiBase::getProfileTime was removed (deprecated since 1.25)
137
138 === Languages updated in 1.31 ===
139 MediaWiki supports over 350 languages. Many localisations are updated
140 regularly. Below only new and removed languages are listed, as well as
141 changes to languages because of Phabricator reports.
142
143 * (T180052) Mirandese (mwl) now supports gendered NS_USER/NS_USER_TALK namespaces.
144 * (T182305) New language support: Nyungar (nys).
145 * (T186359) New language support: Siberian Tatar [cебертатар] (sty).
146 * (T186635) New language support: Guianan Creole (gcr).
147 * (T186647) New language support: Kumyk [къумукъ] (kum).
148 * (T187750) New language support: Spanish formal address (es-formal).
149 * (T187824) New language support: Hungarian formal address (hu-formal).
150
151 === Breaking changes in 1.31 ===
152 * MessageBlobStore::insertMessageBlob() (deprecated in 1.27) was removed.
153 * The OutputPage class constructor now requires a context parameter,
154 (instantiating without context was deprecated in 1.18)
155 * The mw.page JavaScript singleton (deprecated in 1.30) was removed.
156 * Article::getLastPurgeTimestamp(), WikiPage::getLastPurgeTimestamp(), and the
157 related WikiPage::PURGE_* constants, deprecated in 1.29, were removed.
158 * The Article::selectFields(), Article::onArticleCreate(),
159 Article::onArticleDelete(), and Article::onArticleEdit() methods, deprecated
160 in 1.24, were removed.
161 * Installer::locateExecutable() and Installer::locateExecutableInDefaultPaths()
162 were removed, use ExecutableFinder::findInDefaultPaths() instead.
163 * The deprecated MW_DIFF_VERSION constant was removed.
164 DifferenceEngine::MW_DIFF_VERSION should be used instead.
165 * Due to significant refactoring, method ContribsPager::getUserCond() that had
166 no access restriction has been removed.
167 * The Block class will no longer accept usable-but-missing usernames for
168 'byText' or ->setBlocker(). Callers should either ensure the blocker exists
169 locally or use a new interwiki-format username like "iw>Example".
170 * The following methods and constants from the WatchedItem class, which were deprecated in
171 1.27, have been removed.
172 * WatchedItem::getTitle()
173 * WatchedItem::fromUserTitle()
174 * WatchedItem::addWatch()
175 * WatchedItem::removeWatch()
176 * WatchedItem::isWatched()
177 * WatchedItem::duplicateEntries()
178 * WatchedItem::IGNORE_USER_RIGHTS
179 * WatchedItem::CHECK_USER_RIGHTS
180 * WatchedItem::DEPRECATED_USAGE_TIMESTAMP
181 * The $statementsOnOwnLine parameter of JavaScriptMinifier::minify was removed.
182 The corresponding configuration variable ($wgResourceLoaderMinifierStatementsOnOwnLine)
183 has been deprecated since 1.27 and was removed as well.
184 * The $maxLineLength parameter of JavaScriptMinifier::minify was removed.
185 The corresponding configuration variable ($wgResourceLoaderMinifierMaxLineLength)
186 has been deprecated since 1.27 and was removed as well.
187 * The HtmlFormatter class was removed (deprecated in 1.27). The namespaced
188 HtmlFormatter\HtmlFormatter class should be used instead.
189 * The driver 'mysql' for MySQL, deprecated in MediaWiki 1.30, has been removed.
190 The driver has been deprecated since PHP 5.5 and was removed in PHP 7.0. The
191 default driver for MySQL has been 'mysqli' since MediaWiki 1.22.
192 * The following properties of PreparedEdit were deprecated in 1.21 and have been removed:
193 * PreparedEdit->newText
194 * PreparedEdit->oldText
195 * PreparedEdit->pst
196 * ParserOutput objects generated using a non-default value for
197 ParserOptions::setWrapOutputClass() can no longer be added to the parser cache.
198 * The following deprecated methods from the OutputPage class have been removed:
199 * OutputPage::addExtensionStyle(); deprecated in 1.27
200 * OutputPage::getExtStyle(); deprecated in 1.27
201 * OutputPage::setETag(); deprecated in 1.28 (obsolete no-op)
202 * OutputPage::setSquidMaxage(); deprecated in 1.27
203 * OutputPage::readOnlyPage(); deprecated in 1.25
204 * OutputPage::rateLimited(); deprecated in 1.25
205 * Additionally, the protected OutputPage::$mExtStyles array, only accessed through
206 the above and with no known uses, was removed.
207 * The no-op method Skin::showIPinHeader(), deprecated in 1.27, was removed.
208 * The following variables and methods in EditPage, deprecated in MediaWiki 1.30, were removed:
209 * $isCssJsSubpage — use ::isUserConfigPage()
210 * $isCssSubpage — use ::isUserCssConfigPage()
211 * $isJsSubpage — use ::isUserJsConfigPage()
212 * $isWrongCaseCssJsPage – use ::isWrongCaseUserConfigPage()
213 * ::getSummaryInput() – use ::getSummaryInputWidget()
214 * ::getSummaryInputOOUI() – use ::getSummaryInputWidget()
215 * ::getCheckboxes() – use ::getCheckboxesWidget() or ::getCheckboxesDefinition()
216 * ::getCheckboxesOOUI() – use ::getCheckboxesWidget() or ::getCheckboxesDefinition()
217 * The method ResourceLoaderModule::getPosition(), deprecated in 1.29, has been removed.
218 * In User, the cookie-related methods which were wrappers for the functions on the response
219 object, and were deprecated in 1.27, have been removed:
220 * ::setCookie()
221 * ::clearCookie()
222 * ::setExtendedLoginCookie()
223 Note that User::setCookies() remains, and is not deprecated.
224 * Also in User, some auth-related methods which were deprecated in 1.27, have been removed:
225 * ::getEditTokenTimestamp() – use MediaWiki\Session\Token::getTimestamp()
226 * ::getPasswordFactory() – create a PasswordFactory directly
227 * ::passwordChangeInputAttribs()
228 * The global functions wfProfileIn and wfProfileOut, deprecated in 1.25, have been removed.
229 * SpecialPageFactory::getList(), deprecated in 1.24, has been removed. You can
230 use ::getNames() instead.
231 * OpenSearch::getOpenSearchTemplate(), deprecated in 1.25, has been removed. You
232 can use ApiOpenSearch::getOpenSearchTemplate() instead.
233 * The global function wfBaseConvert, deprecated in 1.27, has been removed. Use
234 Wikimedia\base_convert() directly.
235 * Calling Database::begin() explicitly during an implicit transaction or when DBO_TRX
236 is set results in an exception. Calling Database::commit() explicitly for an implicit
237 transaction also results in an exception. Previously these were logged as errors.
238 The startAtomic() and endAtomic() methods, or AtomicSectionUpdate should be used
239 instead.
240 * The global function wfOutputHandler() was removed, use the its replacement
241 MediaWiki\OutputHandler::handle() instead. The global function was only sometimes defined.
242 Its replacement is always available via the autoloader.
243 * ChangeTags::listExtensionActivatedTags and ::listExtensionDefinedTags, deprecated
244 in 1.28, have been removed. Use ::listSoftwareActivatedTags() and
245 ::listSoftwareDefinedTags() instead.
246 * Title::getTitleInvalidRegex(), deprecated in 1.25, has been removed. You
247 can use MediaWikiTitleCodec::getTitleInvalidRegex() instead.
248 * HTMLForm & VFormHTMLForm::isVForm(), deprecated in 1.25, have been removed.
249 * The ProfileSection class, deprecated in 1.25 and unused, has been removed.
250 * The ResourceLoaderGetLessVars hook, deprecated in 1.30, has been removed.
251 Use ResourceLoaderModule::getLessVars() to expose local variables instead
252 of global ones.
253 * As part of work to modernise user-generated content clean-up, a config option and some
254 methods related to HTML validity were removed without deprecation. The public methods
255 MWTidy::checkErrors() and its callee TidyDriverBase::validate() are removed, as are
256 MediaWikiTestCase::assertValidHtmlSnippet() and ::assertValidHtmlDocument(). The
257 $wgValidateAllHtml configuration option is removed and will be ignored.
258 * Execution of external programs using MediaWiki\Shell\Command now applies RESTRICT_DEFAULT
259 Firejail restriction by default.
260
261 === Deprecations in 1.31 ===
262 * The Revision class was deprecated in favor of RevisionStore, BlobStore, and
263 RevisionRecord and its subclasses.
264 * The global function wfBCP47 is deprecated in favour of LanguageCode::bcp47.
265 * The global function wfCountDown is now deprecated in favor of Maintenance::countDown.
266 * Several methods for returning lists of fields to select from the database
267 have been deprecated in favor of similar methods that also return the tables
268 to select from and the join conditions for those tables.
269 * Block::selectFields() → Block::getQueryInfo()
270 * RecentChange::selectFields() → RecentChange::getQueryInfo()
271 * ArchivedFile::selectFields() → ArchivedFile::getQueryInfo()
272 * LocalFile::selectFields() → LocalFile::getQueryInfo()
273 * LocalFile::getCacheFields() with a prefix no longer works
274 * LocalFile::getLazyCacheFields() with a prefix no longer works
275 * OldLocalFile::selectFields() → OldLocalFile::getQueryInfo()
276 * RecentChange::selectFields() → RecentChange::getQueryInfo()
277 * Revision::userJoinCond() → Revision::getQueryInfo( [ 'user' ] )
278 * Revision::selectUserFields() → Revision::getQueryInfo( [ 'user' ] )
279 * Revision::pageJoinCond() → Revision::getQueryInfo( [ 'page' ] )
280 * Revision::selectPageFields() → Revision::getQueryInfo( [ 'page' ] )
281 * Revision::selectTextFields() → Revision::getQueryInfo( [ 'text' ] )
282 * Revision::selectFields() → Revision::getQueryInfo()
283 * Revision::selectArchiveFields() → Revision::getArchiveQueryInfo()
284 * User::selectFields() → User::getQueryInfo()
285 * WikiPage::selectFields() → WikiPage::getQueryInfo()
286 * Revision::setUserIdAndName() was deprecated.
287 * Access to TitleValue class properties was deprecated, the relevant getters
288 should be used instead.
289 * DifferenceEngine::getDiffBodyCacheKey() is deprecated. Subclasses should
290 override DifferenceEngine::getDiffBodyCacheKeyParams() instead.
291 * Use of Maintenance::error( $err, $die ) to exit script was deprecated. Use
292 Maintenance::fatalError() instead.
293 * Passing a ParserOptions object to OutputPage::parserOptions() is deprecated.
294 * The RevisionInsertComplete hook is now deprecated, use RevisionRecordInserted instead.
295 RevisionInsertComplete is still called, but the second and third parameter will always be null.
296 Hard deprecation is scheduled for 1.32.
297 * The following methods that get and set ParserOutput state are deprecated.
298 Callers should use the new stateless $options parameter to
299 ParserOutput::getText() instead.
300 * ParserOptions::getEditSection()
301 * ParserOptions::setEditSection()
302 * ParserOutput::getEditSectionTokens()
303 * ParserOutput::setEditSectionTokens()
304 * ParserOutput::getTOCEnabled()
305 * ParserOutput::setTOCEnabled()
306 * OutputPage::enableSectionEditLinks()
307 * OutputPage::sectionEditLinksEnabled()
308 * The public ParserOutput state fields $mTOCEnabled and $mEditSectionTokens are also deprecated.
309 * License::getLicenses has been deprecated; use License::getLines instead.
310 * QuickTemplate::setRef() was deprecated in favour of QuickTemplate::set().
311 Setting template variables by reference allowed violating the principle of data being
312 immutable once added to the skin template. In practice, this method was not being
313 used for that. Rather, setRef() existed as memory optimisation for PHP 4.
314 * QuickTemplate::setTranslator() was deprecated in favour of Skin::msg() parameters.
315 * MediaWikiI18N::set() was deprecated in favour of Skin::msg() parameters.
316 * MediaWikiI18N::translate() was deprecated in favour of Skin::msg() or wfMessage().
317 * Passing false to ParserOptions::setWrapOutputClass() is deprecated. Use the
318 'unwrap' transform to ParserOutput::getText() instead.
319 * \ObjectFactory (no namespace) is deprecated, the namespaced \Wikimedia\ObjectFactory
320 from the wikimedia/object-factory library should be used instead.
321 * CommentStore::newKey is deprecated. Get an instance from MediaWikiServices instead.
322 * The following CommentStore methods have had their signatures changed to introduce a $key parameter,
323 usage of the methods on instances retrieved from CommentStore::newKey will remain unchanged but deprecated:
324 * CommentStore::getFields
325 * CommentStore::getJoin
326 * CommentStore::getComment
327 * CommentStore::getCommentLegacy
328 * CommentStore::insert
329 * CommentStore::insertWithTemplate
330 * The following methods in Title have been renamed, and the old ones are deprecated:
331 * Title::getSkinFromCssJsSubpage – use ::getSkinFromConfigSubpage
332 * Title::isCssOrJsPage – use ::isSiteConfigPage
333 * Title::isCssJsSubpage – use ::isUserConfigPage
334 * Title::isCssSubpage – use ::isUserCssConfigPage
335 * Title::isJsSubpage – use ::isUserJsConfigPage
336 * The following methods related to caching of half-parsed HTML were deprecated:
337 * Parser::serializeHalfParsedText()
338 * Parser::unserializeHalfParsedText()
339 * Parser::isValidHalfParsedText()
340 * StripState::getSubState()
341 * StripState::merge()
342 * The DeferredStringifier class is deprecated, use Message::listParam() instead.
343 * The type string for the parameter $lang of DateFormatter::getInstance is
344 deprecated.
345 * Wikimedia\Rdbms\SavepointPostgres is deprecated.
346 * The DO_MAINTENANCE constant is deprecated. RUN_MAINTENANCE_IF_MAIN should be
347 used instead.
348 * The function wfShellWikiCmd() has been deprecated, use
349 MediaWiki\Shell::makeScriptCommand().
350
351 === Other changes in 1.31 ===
352 * Browser support for Internet Explorer 10 was lowered from Grade A to Grade C.
353 * Browser support for Opera 12 and older was removed. Opera 15+ continues at Grade A.
354 * Introducing multi-content-revision capability into the storage layer. For details,
355 see <https://www.mediawiki.org/wiki/Requests_for_comment/Multi-Content_Revisions>.
356 * The "free" CSS class is now only applied to unbracketed URLs in wikitext. Links
357 written using square brackets will get the class "text" not "free".
358 * RFC 157418: Whitespace is trimmed from wikitext headings, wikitext list items,
359 wikitext table captions, wikitext table headings, wikitext table cells. HTML
360 headings, HTML list items, HTML table captions, HTML table headings, HTML table cells
361 will not have this trimming behavior.
362
363 == Compatibility ==
364 MediaWiki 1.31 requires PHP 5.5.9 or later. Although HHVM 3.18.5 or later is supported,
365 it is generally advised to use PHP 5.5.9 or later for long term support.
366
367 MySQL/MariaDB is the recommended DBMS. PostgreSQL or SQLite can also be used,
368 but support for them is somewhat less mature. There is experimental support for
369 Oracle and Microsoft SQL Server.
370
371 The supported versions are:
372
373 * MySQL 5.0.3 or later
374 * PostgreSQL 9.2 or later
375 * SQLite 3.3.7 or later
376 * Oracle 9.0.1 or later
377 * Microsoft SQL Server 2005 (9.00.1399)
378
379 == Upgrading ==
380 1.31 has several database changes since 1.30, and will not work without schema
381 updates. Note that due to changes to some very large tables like the revision
382 table, the schema update may take quite long (minutes on a medium sized site,
383 many hours on a large site).
384
385 Don't forget to always back up your database before upgrading!
386
387 See the file UPGRADE for more detailed upgrade instructions, including
388 important information when upgrading from versions prior to 1.11.
389
390 For notes on 1.30.x and older releases, see HISTORY.
391
392 == Online documentation ==
393 Documentation for both end-users and site administrators is available on
394 MediaWiki.org, and is covered under the GNU Free Documentation License (except
395 for pages that explicitly state that their contents are in the public domain):
396
397 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
398
399 == Mailing list ==
400 A mailing list is available for MediaWiki user support and discussion:
401
402 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
403
404 A low-traffic announcements-only list is also available:
405
406 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
407
408 It's highly recommended that you sign up for one of these lists if you're
409 going to run a public MediaWiki, so you can be notified of security fixes.
410
411 == IRC help ==
412 There's usually someone online in #mediawiki on irc.freenode.net.