2022-08-31 12:51:57 +01:00

177 KiB

Synapse 1.66.0 (2022-08-31)

No significant changes since 1.66.0rc2.

This release removes the ability for homeservers to delegate email ownership verification and password reset confirmation to identity servers. This removal was originally planned for Synapse 1.64, but was later deferred until now. See the upgrade notes for more details.

Deployments with multiple workers should note that the direct TCP replication configuration was deprecated in Synapse v1.18.0 and will be removed in Synapse v1.67.0. In particular, the TCP replication listener type (not to be confused with the replication resource on the http listener type) and the worker_replication_port config option will be removed .

To migrate to Redis, add the redis config, then remove the TCP replication listener from config of the master and worker_replication_port from worker config. Note that a HTTP listener with a replication resource is still required. See the worker documentation for more details.

Synapse 1.66.0rc2 (2022-08-30)

Bugfixes

  • Fix a bug introduced in Synapse 1.66.0rc1 where the new rate limit metrics were misreported (synapse_rate_limit_sleep_affected_hosts, synapse_rate_limit_reject_affected_hosts). (#13649)

Synapse 1.66.0rc1 (2022-08-23)

Features

Bugfixes

  • Faster room joins: make /joined_members block whilst the room is partial stated. (#13514)
  • Fix a bug introduced in Synapse 1.21.0 where the /event_reports Admin API could return a total count which was larger than the number of results you can actually query for. (#13525)
  • Fix a bug introduced in Synapse 1.52.0 where sending server notices fails if max_avatar_size or allowed_avatar_mimetypes is set and not system_mxid_avatar_url. (#13566)
  • Fix a bug where the opentracing.force_tracing_for_users config option would not apply to /sendToDevice and /keys/upload requests. (#13574)

Improved Documentation

  • Add openssl example for generating registration HMAC digest. (#13472)
  • Tidy up Synapse's README. (#13491)
  • Document that event purging related to the redaction_retention_period config option is executed only every 5 minutes. (#13492)
  • Add a warning to retention documentation regarding the possibility of database corruption. (#13497)
  • Document that the DOCKER_BUILDKIT=1 flag is needed to build the docker image. (#13515)
  • Add missing links in user_consent section of configuration manual. (#13536)
  • Fix the doc and some warnings that were referring to the nonexistent custom_templates_directory setting (instead of custom_template_directory). (#13538)

Deprecations and Removals

  • Remove the ability for homeservers to delegate email ownership verification and password reset confirmation to identity servers. See upgrade notes for more details.

Internal Changes

Faster room joins

  • Update the rejected state of events during de-partial-stating. (#13459)
  • Avoid blocking lazy-loading /syncs during partial joins due to remote memberships. Pull remote memberships from auth events instead of the room state. (#13477)
  • Refuse to start when faster joins is enabled on a deployment with workers, since worker configurations are not currently supported. (#13531)

Metrics and tracing

  • Allow use of both @trace and @tag_args stacked on the same function. (#13453)
  • Instrument the federation/backfill part of /messages for understandable traces in Jaeger. (#13489)
  • Instrument FederationStateIdsServlet (/state_ids) for understandable traces in Jaeger. (#13499, #13554)
  • Track HTTP response times over 10 seconds from /messages (synapse_room_message_list_rest_servlet_response_time_seconds). (#13533)
  • Add metrics to track how the rate limiter is affecting requests (sleep/reject). (#13534, #13541)
  • Add metrics to time how long it takes us to do backfill processing (synapse_federation_backfill_processing_before_time_seconds, synapse_federation_backfill_processing_after_time_seconds). (#13535, #13584)
  • Add metrics to track rate limiter queue timing (synapse_rate_limit_queue_wait_time_seconds). (#13544)
  • Update metrics to track /messages response time by room size. (#13545)

Everything else

  • Refactor methods in synapse.api.auth.Auth to use Requester objects everywhere instead of user IDs. (#13024)
  • Clean-up tests for notifications. (#13471)
  • Add some miscellaneous comments to document sync, especially around compute_state_delta. (#13474)
  • Use literals in place of HTTPStatus constants in tests. (#13479, #13488)
  • Add comments about how event push actions are rotated. (#13485)
  • Modify HTML template content to better support mobile devices' screen sizes. (#13493)
  • Add a linter script which will reject non-strict types in Pydantic models. (#13502)
  • Reduce the number of tests using legacy TCP replication. (#13543)
  • Allow specifying additional request fields when using the HomeServerTestCase.login helper method. (#13549)
  • Make HomeServerTestCase load any configured homeserver modules automatically. (#13558)

Synapse 1.65.0 (2022-08-16)

No significant changes since 1.65.0rc2.

Synapse 1.65.0rc2 (2022-08-11)

Internal Changes

  • Revert 'Remove the unspecced room_id field in the /hierarchy response. (#13365)' to give more time for clients to update. (#13501)

Synapse 1.65.0rc1 (2022-08-09)

Features

  • Add support for stable prefixes for MSC2285 (private read receipts). (#13273)
  • Add new unstable error codes ORG.MATRIX.MSC3848.ALREADY_JOINED, ORG.MATRIX.MSC3848.NOT_JOINED, and ORG.MATRIX.MSC3848.INSUFFICIENT_POWER described in MSC3848. (#13343)
  • Use stable prefixes for MSC3827. (#13370)
  • Add a new module API method to translate a room alias into a room ID. (#13428)
  • Add a new module API method to create a room. (#13429)
  • Add remote join capability to the module API's update_room_membership method (in a backwards compatible manner). (#13441)

Bugfixes

  • Update the version of the LDAP3 auth provider module included in the matrixdotorg/synapse DockerHub images and the Debian packages hosted on packages.matrix.org to 0.2.2. This version fixes a regression in the module. (#13470)
  • Fix a bug introduced in Synapse v1.41.0 where the /hierarchy API returned non-standard information (a room_id field under each entry in children_state) (this was reverted in v1.65.0rc2, see changelog notes above). (#13365)
  • Fix a bug introduced in Synapse 0.24.0 that would respond with the wrong error status code to /joined_members requests when the requester is not a current member of the room. Contributed by @andrewdoh. (#13374)
  • Fix bug in handling of typing events for appservices. Contributed by Nick @ Beeper (@fizzadar). (#13392)
  • Fix a bug introduced in Synapse 1.57.0 where rooms listed in exclude_rooms_from_sync in the configuration file would not be properly excluded from incremental syncs. (#13408)
  • Fix a bug in the experimental faster-room-joins support which could cause it to get stuck in an infinite loop. (#13353)
  • Faster room joins: fix a bug which caused rejected events to become un-rejected during state syncing. (#13413)
  • Faster room joins: fix error when running out of servers to sync partial state with, so that Synapse raises the intended error instead. (#13432)

Updates to the Docker image

  • Make Docker images build on armv7 by installing cryptography dependencies in the 'requirements' stage. Contributed by Jasper Spaans. (#13372)

Improved Documentation

  • Update the 'registration tokens' page to acknowledge that the relevant MSC was merged into version 1.2 of the Matrix specification. Contributed by @moan0s. (#11897)
  • Document which HTTP resources support gzip compression. (#13221)
  • Add steps describing how to elevate an existing user to administrator by manipulating the database. (#13230)
  • Fix wrong headline for url_preview_accept_language in documentation. (#13437)
  • Remove redundant 'Contents' section from the Configuration Manual. Contributed by @dklimpel. (#13438)
  • Update documentation for config setting macaroon_secret_key. (#13443)
  • Update outdated information on sso_mapping_providers documentation. (#13449)
  • Fix example code in module documentation of password_auth_provider_callbacks. (#13450)
  • Make the configuration for the cache clearer. (#13481)

Internal Changes

  • Extend the release script to automatically push a new SyTest branch, rather than having that be a manual process. (#12978)
  • Make minor clarifications to the error messages given when we fail to join a room via any server. (#13160)
  • Enable Complement CI tests in the 'latest deps' test run. (#13213)
  • Fix long-standing bugged logic which was never hit in get_pdu asking every remote destination even after it finds an event. (#13346)
  • Faster room joins: avoid blocking when pulling events with partially missing prev events. (#13355)
  • Instrument /messages for understandable traces in Jaeger. (#13368)
  • Remove an unused argument to get_relations_for_event. (#13383)
  • Add a merge-back command to the release script, which automates merging the correct branches after a release. (#13393)
  • Adding missing type hints to tests. (#13397)
  • Faster Room Joins: don't leave a stuck room partial state flag if the join fails. (#13403)
  • Refactor _resolve_state_at_missing_prevs to compute an EventContext instead. (#13404, #13431)
  • Faster Room Joins: prevent Synapse from answering federated join requests for a room which it has not fully joined yet. (#13416)
  • Re-enable running Complement tests against Synapse with workers. (#13420)
  • Prevent unnecessary lookups to any external get_event cache. Contributed by Nick @ Beeper (@fizzadar). (#13435)
  • Add some tracing to give more insight into local room joins. (#13439)
  • Rename class RateLimitConfig to RatelimitSettings and FederationRateLimitConfig to FederationRatelimitSettings. (#13442)
  • Add some comments about how event push actions are stored. (#13445, #13455)
  • Improve rebuild speed for the "synapse-workers" docker image. (#13447)
  • Fix @tag_args being off-by-one with the arguments when tagging a span (tracing). (#13452)
  • Update type of EventContext.rejected. (#13460)
  • Use literals in place of HTTPStatus constants in tests. (#13463, #13469)
  • Correct a misnamed argument in state res v2 internals. (#13467)

Synapse 1.64.0 (2022-08-02)

No significant changes since 1.64.0rc2.

Deprecation Warning

Synapse v1.66.0 will remove the ability to delegate the tasks of verifying email address ownership, and password reset confirmation, to an identity server.

If you require your homeserver to verify e-mail addresses or to support password resets via e-mail, please configure your homeserver with SMTP access so that it can send e-mails on its own behalf. Consult the configuration documentation for more information.

Synapse 1.64.0rc2 (2022-07-29)

This RC reintroduces support for account_threepid_delegates.email, which was removed in 1.64.0rc1. It remains deprecated and will be removed altogether in Synapse v1.66.0. (#13406)

Synapse 1.64.0rc1 (2022-07-26)

This RC removed the ability to delegate the tasks of verifying email address ownership, and password reset confirmation, to an identity server.

We have also stopped building .deb packages for Ubuntu 21.10 as it is no longer an active version of Ubuntu.

Features

  • Improve error messages when media thumbnails cannot be served. (#13038)
  • Allow pagination from remote event after discovering it from MSC3030 /timestamp_to_event. (#13205)
  • Add a room_type field in the responses for the list room and room details admin APIs. Contributed by @andrewdoh. (#13208)
  • Add support for room version 10. (#13220)
  • Add per-room rate limiting for room joins. For each room, Synapse now monitors the rate of join events in that room, and throttles additional joins if that rate grows too large. (#13253, #13254, #13255, #13276)
  • Support Implicit TLS (TLS without using a STARTTLS upgrade, typically on port 465) for sending emails, enabled by the new option force_tls. Contributed by Jan Schär. (#13317)

Bugfixes

  • Fix a bug introduced in Synapse 1.15.0 where adding a user through the Synapse Admin API with a phone number would fail if the enable_email_notifs and email_notifs_for_new_users options were enabled. Contributed by @thomasweston12. (#13263)
  • Fix a bug introduced in Synapse 1.40.0 where a user invited to a restricted room would be briefly unable to join. (#13270)
  • Fix a long-standing bug where, in rare instances, Synapse could store the incorrect state for a room after a state resolution. (#13278)
  • Fix a bug introduced in v1.18.0 where the synapse_pushers metric would overcount pushers when they are replaced. (#13296)
  • Disable autocorrection and autocapitalisation on the username text field shown during registration when using SSO. (#13350)
  • Update locked version of frozendict to 2.3.3, which has fixes for memory leaks affecting /sync. (#13284, #13352)

Improved Documentation

  • Provide an example of using the Admin API. Contributed by @jejo86. (#13231)
  • Move the documentation for how URL previews work to the URL preview module. (#13233, #13261)
  • Add another contrib script to help set up worker processes. Contributed by @villepeh. (#13271)
  • Document that certain config options were added or changed in Synapse 1.62. Contributed by @behrmann. (#13314)
  • Document the new rc_invites.per_issuer throttling option added in Synapse 1.63. (#13333)
  • Mention that BuildKit is needed when building Docker images for tests. (#13338)
  • Improve Caddy reverse proxy documentation. (#13344)

Deprecations and Removals

  • Drop tables that were formerly used for groups/communities. (#12967)
  • Drop support for delegating email verification to an external server. (#13192)
  • Drop support for calling /_matrix/client/v3/account/3pid/bind without an id_access_token, which was not permitted by the spec. Contributed by @Vetchu. (#13239)
  • Stop building .deb packages for Ubuntu 21.10 (Impish Indri), which has reached end of life. (#13326)

Internal Changes

  • Use lower transaction isolation level when purging rooms to avoid serialization errors. Contributed by Nick @ Beeper. (#12942)
  • Remove code which incorrectly attempted to reconcile state with remote servers when processing incoming events. (#12943)
  • Make the AS login method call Auth.get_user_by_req for checking the AS token. (#13094)
  • Always use a version of canonicaljson that supports the C implementation of frozendict. (#13172)
  • Add prometheus counters for ephemeral events and to device messages pushed to app services. Contributed by Brad @ Beeper. (#13175)
  • Refactor receipts servlet logic to avoid duplicated code. (#13198)
  • Preparation for database schema simplifications: populate state_key and rejection_reason for existing rows in the events table. (#13215)
  • Remove unused database table event_reference_hashes. (#13218)
  • Further reduce queries used sending events when creating new rooms. Contributed by Nick @ Beeper (@fizzadar). (#13224)
  • Call the v2 identity service /3pid/unbind endpoint, rather than v1. Contributed by @Vetchu. (#13240)
  • Use an asynchronous cache wrapper for the get event cache. Contributed by Nick @ Beeper (@fizzadar). (#13242, #13308)
  • Optimise federation sender and appservice pusher event stream processing queries. Contributed by Nick @ Beeper (@fizzadar). (#13251)
  • Log the stack when waiting for an entire room to be un-partial stated. (#13257)
  • Fix spurious warning when fetching state after a missing prev event. (#13258)
  • Clean-up tests for notifications. (#13260)
  • Do not fail build if complement with workers fails. (#13266)
  • Don't pull out state in compute_event_context for unconflicted state. (#13267, #13274)
  • Reduce the rebuild time for the complement-synapse docker image. (#13279)
  • Don't pull out the full state when creating an event. (#13281, #13307)
  • Upgrade from Poetry 1.1.12 to 1.1.14, to fix bugs when locking packages. (#13285)
  • Make DictionaryCache expire full entries if they haven't been queried in a while, even if specific keys have been queried recently. (#13292)
  • Use HTTPStatus constants in place of literals in tests. (#13297)
  • Improve performance of query _get_subset_users_in_room_with_profiles. (#13299)
  • Up batch size of bulk_get_push_rules and _get_joined_profiles_from_event_ids. (#13300)
  • Remove unnecessary json.dumps from tests. (#13303)
  • Reduce memory usage of sending dummy events. (#13310)
  • Prevent formatting changes of #3679 from appearing in git blame. (#13311)
  • Change get_users_in_room and get_rooms_for_user caches to enable pruning of old entries. (#13313)
  • Validate federation destinations and log an error if a destination is invalid. (#13318)
  • Fix FederationClient.get_pdu() returning events from the cache as outliers instead of original events we saw over federation. (#13320)
  • Reduce memory usage of state caches. (#13323)
  • Reduce the amount of state we store in the state_cache. (#13324)
  • Add missing type hints to open tracing module. (#13328, #13345, #13362)
  • Remove old base slaved store and de-duplicate cache ID generators. Contributed by Nick @ Beeper (@fizzadar). (#13329, #13349)
  • When reporting metrics is enabled, use ~8x less data to describe DB transaction metrics. (#13342)
  • Faster room joins: skip soft fail checks while Synapse only has partial room state, since the current membership of event senders may not be accurately known. (#13354)

Synapse 1.63.1 (2022-07-20)

Bugfixes

  • Fix a bug introduced in Synapse 1.63.0 where push actions were incorrectly calculated for appservice users. This caused performance issues on servers with large numbers of appservices. (#13332)

Synapse 1.63.0 (2022-07-19)

Improved Documentation

  • Clarify that homeserver server names are included in the reported data when the report_stats config option is enabled. (#13321)

Synapse 1.63.0rc1 (2022-07-12)

Features

  • Add a rate limit for local users sending invites. (#13125)
  • Implement MSC3827: Filtering of /publicRooms by room type. (#13031)
  • Improve validation logic in the account data REST endpoints. (#13148)

Bugfixes

  • Fix a long-standing bug where application services were not able to join remote federated rooms without a profile. (#13131)
  • Fix a long-standing bug where _get_state_map_for_room might raise errors when third party event rules callbacks are present. (#13174)
  • Fix a long-standing bug where the synapse_port_db script could fail to copy rows with negative row ids. (#13226)
  • Fix a bug introduced in 1.54.0 where appservices would not receive room-less EDUs, like presence, when both MSC2409 and MSC3202 are enabled. (#13236)
  • Fix a bug introduced in 1.62.0 where rows were not deleted from event_push_actions table on large servers. (#13194)
  • Fix a bug introduced in 1.62.0 where notification counts would get stuck after a highlighted message. (#13223)
  • Fix exception when using experimental MSC3030 /timestamp_to_event endpoint to look for remote federated imported events before room creation. (#13197)
  • Fix MSC3202-enabled appservices not receiving to-device messages, preventing messages from being decrypted. (#13235)

Updates to the Docker image

  • Bump the version of lxml in matrix.org Docker images Debian packages from 4.8.0 to 4.9.1. (#13207)

Improved Documentation

  • Add an explanation of the --report-stats argument to the docs. (#13029)
  • Add a helpful example bash script to the contrib directory for creating multiple worker configuration files of the same type. Contributed by @villepeh. (#13032)
  • Add missing links to config options. (#13166)
  • Add documentation for homeserver usage statistics collection. (#13086)
  • Add documentation for the existing databases option in the homeserver configuration manual. (#13212)
  • Clean up references to sample configuration and redirect users to the configuration manual instead. (#13077, #13139)
  • Document how the Synapse team does reviews. (#13132)
  • Fix wrong section header for allow_public_rooms_over_federation in the homeserver config documentation. (#13116)

Deprecations and Removals

  • Remove obsolete and for 8 years unused RoomEventsStoreTestCase. Contributed by @arkamar. (#13200)

Internal Changes

  • Add type annotations to synapse.logging, tests.server and tests.utils. (#13028, #13103, #13159, #13136)
  • Enforce type annotations for tests.test_server. (#13135)
  • Support temporary experimental return values for spam checker module callbacks. (#13044)
  • Add support to complement.sh for skipping the docker build. (#13143, #13158)
  • Add support to complement.sh for setting the log level using the SYNAPSE_TEST_LOG_LEVEL environment variable. (#13152)
  • Enable Complement testing in the 'Twisted Trunk' CI runs. (#13079, #13157)
  • Improve startup times in Complement test runs against workers, particularly in CPU-constrained environments. (#13127)
  • Update config used by Complement to allow device name lookup over federation. (#13167)
  • Faster room joins: handle race between persisting an event and un-partial stating a room. (#13100)
  • Faster room joins: fix race in recalculation of current room state. (#13151)
  • Faster room joins: skip waiting for full state when processing incoming events over federation. (#13144)
  • Raise a DependencyError on missing dependencies instead of a ConfigError. (#13113)
  • Avoid stripping line breaks from SQL sent to the database. (#13129)
  • Apply ratelimiting earlier in processing of /send requests. (#13134)
  • Improve exception handling when processing events received over federation. (#13145)
  • Check that auto_vacuum is disabled when porting a SQLite database to Postgres, as VACUUMs must not be performed between runs of the script. (#13195)
  • Reduce DB usage of /sync when a large number of unread messages have recently been sent in a room. (#13119, #13153)
  • Reduce memory consumption when processing incoming events in large rooms. (#13078, #13222)
  • Reduce number of queries used to get profile information. Contributed by Nick @ Beeper (@fizzadar). (#13209)
  • Reduce number of events queried during room creation. Contributed by Nick @ Beeper (@fizzadar). (#13210)
  • More aggressively rotate push actions. (#13211)
  • Add max_line_length setting for Python files to the .editorconfig. Contributed by @sumnerevans @ Beeper. (#13228)

Synapse 1.62.0 (2022-07-05)

No significant changes since 1.62.0rc3.

Authors of spam-checker plugins should consult the upgrade notes to learn about the enriched signatures for spam checker callbacks, which are supported with this release of Synapse.

Security advisory

The following issue is fixed in 1.62.0.

  • GHSA-jhjh-776m-4765 / CVE-2022-31152

    Synapse instances prior to 1.62.0 did not implement the Matrix event authorization rules correctly. An attacker could craft events which would be accepted by Synapse but not a spec-conformant server, potentially causing divergence in the room state between servers.

    Homeservers with federation disabled via the federation_domain_whitelist config option are unaffected.

    Administrators of homeservers with federation enabled are advised to upgrade to v1.62.0 or higher.

    Fixed by #13087 and #13088.

Synapse 1.62.0rc3 (2022-07-04)

Bugfixes

  • Update the version of the ldap3 plugin included in the matrixdotorg/synapse DockerHub images and the Debian packages hosted on packages.matrix.org to 0.2.1. This fixes a bug with usernames containing uppercase characters. (#13156)
  • Fix a bug introduced in Synapse 1.62.0rc1 affecting unread counts for users on small servers. (#13168)

Synapse 1.62.0rc2 (2022-07-01)

Bugfixes

  • Fix unread counts for users on large servers. Introduced in v1.62.0rc1. (#13140)
  • Fix DB performance when deleting old push notifications. Introduced in v1.62.0rc1. (#13141)

Synapse 1.62.0rc1 (2022-06-28)

Features

  • Port the spam-checker API callbacks to a new, richer API. This is part of an ongoing change to let spam-checker modules inform users of the reason their event or operation is rejected. (#12857, #13047)
  • Allow server admins to customise the response of the /.well-known/matrix/client endpoint. (#13035)
  • Add metrics measuring the CPU and DB time spent in state resolution. (#13036)
  • Speed up fetching of device list changes in /sync and /keys/changes. (#13045, #13098)
  • Improve URL previews for sites which only provide Twitter Card metadata, e.g. LWN.net. (#13056)

Bugfixes

  • Update MSC3786 implementation to check state_key. (#12939)
  • Fix a bug introduced in Synapse 1.58 where Synapse would not report full version information when installed from a git checkout. This is a best-effort affair and not guaranteed to be stable. (#12973)
  • Fix a bug introduced in Synapse 1.60 where Synapse would fail to start if the sqlite3 module was not available. (#12979)
  • Fix a bug where non-standard information was required when requesting the /hierarchy API over federation. Introduced in Synapse v1.41.0. (#12991)
  • Fix a long-standing bug which meant that rate limiting was not restrictive enough in some cases. (#13018)
  • Fix a bug introduced in Synapse 1.58 where profile requests for a malformed user ID would ccause an internal error. Synapse now returns 400 Bad Request in this situation. (#13041)
  • Fix some inconsistencies in the event authentication code. (#13087, #13088)
  • Fix a long-standing bug where room directory requests would cause an internal server error if given a malformed room alias. (#13106)

Improved Documentation

  • Add documentation for how to configure Synapse with Workers using Docker Compose. Includes example worker config and docker-compose.yaml. Contributed by @Thumbscrew. (#12737)
  • Ensure the Poetry cheat sheet is available in the online documentation. (#13022)
  • Mention removed community/group worker endpoints in upgrade.md. Contributed by @olmari. (#13023)
  • Add instructions for running Complement with gotestfmt-formatted output locally. (#13073)
  • Update OpenTracing docs to reference the configuration manual rather than the configuration file. (#13076)
  • Update information on downstream Debian packages. (#13095)
  • Remove documentation for the Delete Group Admin API which no longer exists. (#13112)

Deprecations and Removals

  • Remove the unspecced DELETE /directory/list/room/{roomId} endpoint, which hid rooms from the public room directory. Instead, PUT to the same URL with a visibility of "private". (#13123)

Internal Changes

  • Add tests for cancellation of GET /rooms/$room_id/members and GET /rooms/$room_id/state requests. (#12674)
  • Report login failures due to unknown third party identifiers in the same way as failures due to invalid passwords. This prevents an attacker from using the error response to determine if the identifier exists. Contributed by Daniel Aloni. (#12738)
  • Merge the Complement testing Docker images into a single, multi-purpose image. (#12881, #13075)
  • Simplify the database schema for event_edges. (#12893)
  • Clean up the test code for client disconnection. (#12929)
  • Remove code generating comments in configuration. (#12941)
  • Add Cross-Origin-Resource-Policy: cross-origin header to content repository's thumbnail and download endpoints. (#12944)
  • Replace noop background updates with DELETE delta. (#12954, #13050)
  • Use lower isolation level when inserting read receipts to avoid serialization errors. Contributed by Nick @ Beeper. (#12957)
  • Reduce the amount of state we pull from the DB. (#12963)
  • Enable testing against PostgreSQL databases in Complement CI. (#12965, #13034)
  • Fix an inaccurate comment. (#12969)
  • Remove the delete_device method and always call delete_devices. (#12970)
  • Use a GitHub form for issues rather than a hard-to-read, easy-to-ignore template. (#12982)
  • Move MSC3715 behind an experimental config flag. (#12984)
  • Add type hints to tests. (#12985, #13099)
  • Refactor macaroon tokens generation and move the unsubscribe link in notification emails to /_synapse/client/unsubscribe. (#12986)
  • Fix documentation for running complement tests. (#12990)
  • Faster joins: add issue links to the TODO comments in the code. (#13004)
  • Reduce DB usage of /sync when a large number of unread messages have recently been sent in a room. (#13005, #13096, #13118)
  • Replaced usage of PyJWT with methods from Authlib in org.matrix.login.jwt. Contributed by Hannes Lerchl. (#13011)
  • Modernize the contrib/graph/ scripts. (#13013)
  • Remove redundant room_version parameters from event auth functions. (#13017)
  • Decouple synapse.api.auth_blocking.AuthBlocking from synapse.api.auth.Auth. (#13021)
  • Add type annotations to synapse.storage.databases.main.devices. (#13025)
  • Set default sync_response_cache_duration to two minutes. (#13042)
  • Rename CI test runs. (#13046)
  • Increase timeout of complement CI test runs. (#13048)
  • Refactor entry points so that they all have a main function. (#13052)
  • Refactor the Dockerfile-workers configuration script to use Jinja2 templates in Synapse workers' Supervisord blocks. (#13054)
  • Add headers to individual options in config documentation to allow for linking. (#13055)
  • Make Complement CI logs easier to read. (#13057, #13058, #13069)
  • Don't instantiate modules with keyword arguments. (#13060)
  • Fix type checking errors against Twisted trunk. (#13061)
  • Allow MSC3030 timestamp_to_event calls from anyone on world-readable rooms. (#13062)
  • Add a CI job to check that schema deltas are in the correct folder. (#13063)
  • Avoid rechecking event auth rules which are independent of room state. (#13065)
  • Reduce the duplication of code that invokes the rate limiter. (#13070)
  • Add a Subject Alternative Name to the certificate generated for Complement tests. (#13071)
  • Add more tests for room upgrades. (#13074)
  • Pin dependencies maintained by matrix.org to semantic version bounds. (#13082)
  • Correctly report prometheus DB stats for get_earliest_token_for_stats. (#13085)
  • Fix a long-standing bug where a finished logging context would be re-started when Synapse failed to persist an event from federation. (#13089)
  • Simplify the alias deletion logic as an application service. (#13093)
  • Add type annotations to tests.test_server. (#13124)

Synapse 1.61.1 (2022-06-28)

This patch release fixes a security issue regarding URL previews, affecting all prior versions of Synapse. Server administrators are encouraged to update Synapse as soon as possible. We are not aware of these vulnerabilities being exploited in the wild.

Server administrators who are unable to update Synapse may use the workarounds described in the linked GitHub Security Advisory below.

Security advisory

The following issue is fixed in 1.61.1.

  • GHSA-22p3-qrh9-cx32 / CVE-2022-31052

    Synapse instances with the url_preview_enabled homeserver config option set to true are affected. URL previews of some web pages can lead to unbounded recursion, causing the request to either fail, or in some cases crash the running Synapse process.

    Requesting URL previews requires authentication. Nevertheless, it is possible to exploit this maliciously, either by malicious users on the homeserver, or by remote users sending URLs that a local user's client may automatically request a URL preview for.

    Homeservers with the url_preview_enabled configuration option set to false (the default) are unaffected. Instances with the enable_media_repo configuration option set to false are also unaffected, as this also disables URL preview functionality.

    Fixed by fa1308061802ac7b7d20e954ba7372c5ac292333.

Synapse 1.61.0 (2022-06-14)

This release removes support for the non-standard feature known both as 'groups' and as 'communities', which have been superseded by Spaces.

See the upgrade notes for more details.

Improved Documentation

Synapse 1.61.0rc1 (2022-06-07)

Features

  • Add new media_retention options to the homeserver config for routinely cleaning up non-recently accessed media. (#12732, #12972, #12977)
  • Experimental support for MSC3772: Push rule for mutually related events. (#12740, #12859)
  • Update to the check_event_for_spam module callback: Deprecate the current callback signature, replace it with a new signature that is both less ambiguous (replacing booleans with explicit allow/block) and more powerful (ability to return explicit error codes). (#12808)
  • Add storage and module API methods to get monthly active users (and their corresponding appservices) within an optionally specified time range. (#12838, #12917)
  • Support the new error code ORG.MATRIX.MSC3823.USER_ACCOUNT_SUSPENDED from MSC3823. (#12845, #12923)
  • Add a configurable background job to delete stale devices. (#12855)
  • Improve URL previews for pages with empty elements. (#12951)
  • Allow updating a user's password using the admin API without logging out their devices. Contributed by @jcgruenhage. (#12952)

Bugfixes

  • Always send an access_token in /thirdparty/ requests to appservices, as required by the Application Service API specification. (#12746)
  • Implement MSC3816: sending the root event in a thread should count as having 'participated' in it. (#12766)
  • Delete events from the federation_inbound_events_staging table when a room is purged through the admin API. (#12784)
  • Fix a bug where we did not correctly handle invalid device list updates over federation. Contributed by Carl Bordum Hansen. (#12829)
  • Fix a bug which allowed multiple async operations to access database locks concurrently. Contributed by @sumnerevans @ Beeper. (#12832)
  • Fix an issue introduced in Synapse 0.34 where the /notifications endpoint would only return notifications if a user registered at least one pusher. Contributed by Famedly. (#12840)
  • Fix a bug where servers using a Postgres database would fail to backfill from an insertion event when MSC2716 is enabled (experimental_features.msc2716_enabled). (#12843)
  • Fix MSC3787 rooms being omitted from room directory, room summary and space hierarchy responses. (#12858)
  • Fix a bug introduced in Synapse 1.54.0 which could sometimes cause exceptions when handling federated traffic. (#12877)
  • Fix a bug introduced in Synapse 1.59.0 which caused room deletion to fail with a foreign key violation error. (#12889)
  • Fix a long-standing bug which caused the /messages endpoint to return an incorrect end attribute when there were no more events. Contributed by @Vetchu. (#12903)
  • Fix a bug introduced in Synapse 1.58.0 where /sync would fail if the most recent event in a room was a redaction of an event that has since been purged. (#12905)
  • Fix a potential memory leak when generating thumbnails. (#12932)
  • Fix a long-standing bug where a URL preview would break if the image failed to download. (#12950)

Improved Documentation

  • Fix typographical errors in documentation. (#12863)
  • Fix documentation incorrectly stating the sendToDevice endpoint can be directed at generic workers. Contributed by Nick @ Beeper. (#12867)

Deprecations and Removals

  • Remove support for the non-standard groups/communities feature from Synapse. (#12553, #12558, #12563, #12895, #12897, #12899, #12900, #12936, #12966)
  • Remove contributed kick_users.py script. This is broken under Python 3, and is not added to the environment when pip installing Synapse. (#12908)
  • Remove contrib/jitsimeetbridge. This was an unused experiment that hasn't been meaningfully changed since 2014. (#12909)
  • Remove unused contrib/experiements/cursesio.py script, which fails to run under Python 3. (#12910)
  • Remove unused contrib/experiements/test_messaging.py script. This fails to run on Python 3. (#12911)

Internal Changes

  • Test Synapse against Complement with workers. (#12810, #12933)
  • Reduce the amount of state we pull from the DB. (#12811, #12964)
  • Try other homeservers when re-syncing state for rooms with partial state. (#12812)
  • Resume state re-syncing for rooms with partial state after a Synapse restart. (#12813)
  • Remove Mutual Rooms' (MSC2666) endpoint dependency on the User Directory. (#12836)
  • Experimental: expand check_event_for_spam with ability to return additional fields. This enables spam-checker implementations to experiment with mechanisms to give users more information about why they are blocked and whether any action is needed from them to be unblocked. (#12846)
  • Remove dont_notify from the .m.rule.room.server_acl rule. (#12849)
  • Remove the unstable /hierarchy endpoint from MSC2946. (#12851)
  • Pull out less state when handling gaps in room DAG. (#12852, #12904)
  • Clean-up the push rules datastore. (#12856)
  • Correct a type annotation in the URL preview source code. (#12860)
  • Update pyjwt dependency to 2.4.0. (#12865)
  • Enable the /account/whoami endpoint on synapse worker processes. Contributed by Nick @ Beeper. (#12866)
  • Enable the batch_send endpoint on synapse worker processes. Contributed by Nick @ Beeper. (#12868)
  • Don't generate empty AS transactions when the AS is flagged as down. Contributed by Nick @ Beeper. (#12869)
  • Fix up the variable state_store naming. (#12871)
  • Faster room joins: when querying the current state of the room, wait for state to be populated. (#12872)
  • Avoid running queries which will never result in deletions. (#12879)
  • Use constants for EDU types. (#12884)
  • Reduce database load of /sync when presence is enabled. (#12885)
  • Refactor have_seen_events to reduce memory consumed when processing federation traffic. (#12886)
  • Refactor receipt linearization code. (#12888)
  • Add type annotations to synapse.logging.opentracing. (#12894)
  • Remove PyNaCl occurrences directly used in Synapse code. (#12902)
  • Bump types-jsonschema from 4.4.1 to 4.4.6. (#12912)
  • Rename storage classes. (#12913)
  • Preparation for database schema simplifications: stop reading from event_edges.room_id. (#12914)
  • Check if we are in a virtual environment before overriding the PYTHONPATH environment variable in the demo script. (#12916)
  • Improve the logging when signature checks on events fail. (#12925)

Synapse 1.60.0 (2022-05-31)

This release of Synapse adds a unique index to the state_group_edges table, in order to prevent accidentally introducing duplicate information (for example, because a database backup was restored multiple times). If your Synapse database already has duplicate rows in this table, this could fail with an error and require manual remediation.

Additionally, the signature of the check_event_for_spam module callback has changed. The previous signature has been deprecated and remains working for now. Module authors should update their modules to use the new signature where possible.

See the upgrade notes for more details.

Bugfixes

  • Fix a bug introduced in Synapse 1.60.0rc1 that would break some imports from synapse.module_api. (#12918)

Synapse 1.60.0rc2 (2022-05-27)

Features

  • Add an option allowing users to use their password to reauthenticate for privileged actions even though password login is disabled. (#12883)

Bugfixes

  • Explicitly close ijson coroutines once we are done with them, instead of leaving the garbage collector to close them. (#12875)

Internal Changes

  • Improve URL previews by not including the content of media tags in the generated description. (#12887)

Synapse 1.60.0rc1 (2022-05-24)

Features

  • Measure the time taken in spam-checking callbacks and expose those measurements as metrics. (#12513)
  • Add a default_power_level_content_override config option to set default room power levels per room preset. (#12618)
  • Add support for MSC3787: Allowing knocks to restricted rooms. (#12623)
  • Send USER_IP commands on a different Redis channel, in order to reduce traffic to workers that do not process these commands. (#12672, #12809)
  • Synapse will now reload cache config when it receives a SIGHUP signal. (#12673)
  • Add a config options to allow for auto-tuning of caches. (#12701)
  • Update MSC2716 implementation to process marker events from the current state to avoid markers being lost in timeline gaps for federated servers which would cause the imported history to be undiscovered. (#12718)
  • Add a drop_federated_event callback to SpamChecker to disregard inbound federated events before they take up much processing power, in an emergency. (#12744)
  • Implement MSC3818: Copy room type on upgrade. (#12786, #12792)
  • Update to the check_event_for_spam module callback. Deprecate the current callback signature, replace it with a new signature that is both less ambiguous (replacing booleans with explicit allow/block) and more powerful (ability to return explicit error codes). (#12808)

Bugfixes

  • Fix a bug introduced in Synapse 1.7.0 that would prevent events from being sent to clients if there's a retention policy in the room when the support for retention policies is disabled. (#12611)
  • Fix a bug introduced in Synapse 1.57.0 where /messages would throw a 500 error when querying for a non-existent room. (#12683)
  • Add a unique index to state_group_edges to prevent duplicates being accidentally introduced and the consequential impact to performance. (#12687)
  • Fix a long-standing bug where an empty room would be created when a user with an insufficient power level tried to upgrade a room. (#12696)
  • Fix a bug introduced in Synapse 1.30.0 where empty rooms could be automatically created if a monthly active users limit is set. (#12713)
  • Fix push to dismiss notifications when read on another client. Contributed by @SpiritCroc @ Beeper. (#12721)
  • Fix poor database performance when reading the cache invalidation stream for large servers with lots of workers. (#12747)
  • Fix a long-standing bug where the user directory background process would fail to make forward progress if a user included a null codepoint in their display name or avatar. (#12762)
  • Delete events from the federation_inbound_events_staging table when a room is purged through the admin API. (#12770)
  • Give a meaningful error message when a client tries to create a room with an invalid alias localpart. (#12779)
  • Fix a bug introduced in 1.43.0 where a file (providers.json) was never closed. Contributed by @arkamar. (#12794)
  • Fix a long-standing bug where finished log contexts would be re-started when failing to contact remote homeservers. (#12803)
  • Fix a bug, introduced in Synapse 1.21.0, that led to media thumbnails being unusable before the index has been added in the background. (#12823)

Updates to the Docker image

  • Fix the docker file after a dependency update. (#12853)

Improved Documentation

  • Fix a typo in the Media Admin API documentation. (#12715)
  • Update the OpenID Connect example for Keycloak to be compatible with newer versions of Keycloak. Contributed by @nhh. (#12727)
  • Fix typo in server listener documentation. (#12742)
  • Link to the configuration manual from the welcome page of the documentation. (#12748)
  • Fix typo in run_background_tasks_on option name in configuration manual documentation. (#12749)
  • Add information regarding the rc_invites ratelimiting option to the configuration docs. (#12759)
  • Add documentation for cancellation of request processing. (#12761)
  • Recommend using docker to run tests against postgres. (#12765)
  • Add missing user directory endpoint from the generic worker documentation. Contributed by @olmari. (#12773)
  • Add additional info to documentation of config option cache_autotuning. (#12776)
  • Update configuration manual documentation to document size-related suffixes. (#12777)
  • Fix invalid YAML syntax in the example documentation for the url_preview_accept_language config option. (#12785)

Deprecations and Removals

  • Require a body in POST requests to /rooms/{roomId}/receipt/{receiptType}/{eventId}, as required by the Matrix specification. This breaks compatibility with Element Android 1.2.0 and earlier: users of those clients will be unable to send read receipts. (#12709)

Internal Changes

  • Improve event caching mechanism to avoid having multiple copies of an event in memory at a time. (#10533)
  • Preparation for faster-room-join work: return subsets of room state which we already have, immediately. (#12498)
  • Add @cancellable decorator, for use on endpoint methods that can be cancelled when clients disconnect. (#12586, #12588, #12630, #12694, #12698, #12699, #12700, #12705)
  • Enable cancellation of GET /rooms/$room_id/members, GET /rooms/$room_id/state and GET /rooms/$room_id/state/$event_type/* requests. (#12708)
  • Improve documentation of the synapse.push module. (#12676)
  • Refactor functions to on PushRuleEvaluatorForEvent. (#12677)
  • Preparation for database schema simplifications: stop writing to event_reference_hashes. (#12679)
  • Remove code which updates unused database column application_services_state.last_txn. (#12680)
  • Refactor EventContext class. (#12689)
  • Remove an unneeded class in the push code. (#12691)
  • Consolidate parsing of relation information from events. (#12693)
  • Convert namespace class Codes into a string enum. (#12703)
  • Optimize private read receipt filtering. (#12711)
  • Drop the logging level of status messages for the URL preview cache expiry job from INFO to DEBUG. (#12720)
  • Downgrade some OIDC errors to warnings in the logs, to reduce the noise of Sentry reports. (#12723)
  • Update configs used by Complement to allow more invites/3PID validations during tests. (#12731)
  • Tweak the mypy plugin so that @cached can accept on_invalidate=None. (#12769)
  • Move methods that call add_push_rule to the PushRuleStore class. (#12772)
  • Make handling of federation Authorization header (more) compliant with RFC7230. (#12774)
  • Refactor resolve_state_groups_for_events to not pull out full state when no state resolution happens. (#12775)
  • Do not keep going if there are 5 back-to-back background update failures. (#12781)
  • Fix federation when using the demo scripts. (#12783)
  • The hash_password script now fails when it is called without specifying a config file. Contributed by @jae1911. (#12789)
  • Improve and fix type hints. (#12567, #12477, #12717, #12753, #12695, #12734, #12716, #12726, #12790, #12833)
  • Update EventContext get_current_event_ids and get_prev_event_ids to accept state filters and update calls where possible. (#12791)
  • Remove Caddy from the Synapse workers image used in Complement. (#12818)
  • Add Complement's shared registration secret to the Complement worker image. This fixes tests that depend on it. (#12819)
  • Support registering Application Services when running with workers under Complement. (#12826)
  • Disable 'faster room join' Complement tests when testing against Synapse with workers. (#12842)

Synapse 1.59.1 (2022-05-18)

This release fixes a long-standing issue which could prevent Synapse's user directory for updating properly.

Bugfixes

  • Fix a long-standing bug where the user directory background process would fail to make forward progress if a user included a null codepoint in their display name or avatar. Contributed by Nick @ Beeper. (#12762)

Synapse 1.59.0 (2022-05-17)

Synapse 1.59 makes several changes that server administrators should be aware of:

  • Device name lookup over federation is now disabled by default. (#12616)
  • The synapse.app.appservice and synapse.app.user_dir worker application types are now deprecated. (#12452, #12654)

See the upgrade notes for more details.

Additionally, this release removes the non-standard m.login.jwt login type from Synapse. It can be replaced with org.matrix.login.jwt for identical behaviour. This is only used if jwt_config.enabled is set to true in the configuration. (#12597)

Bugfixes

  • Fix DB performance regression introduced in Synapse 1.59.0rc2. (#12745)

Synapse 1.59.0rc2 (2022-05-16)

Note: this release candidate includes a performance regression which can cause database disruption. Other release candidates in the v1.59.0 series are not affected, and a fix will be included in the v1.59.0 final release.

Bugfixes

  • Fix a bug introduced in Synapse 1.58.0 where /sync would fail if the most recent event in a room was rejected. (#12729)

Synapse 1.59.0rc1 (2022-05-10)

Features

  • Support MSC3266 room summaries over federation. (#11507)
  • Implement changes to MSC2285 (hidden read receipts). Contributed by @SimonBrandner. (#12168, #12635, #12636, #12670)
  • Extend the module API to allow modules to change actions for existing push rules of local users. (#12406)
  • Add the notify_appservices_from_worker configuration option (superseding notify_appservices) to allow a generic worker to be designated as the worker to send traffic to Application Services. (#12452)
  • Add the update_user_directory_from_worker configuration option (superseding update_user_directory) to allow a generic worker to be designated as the worker to update the user directory. (#12654)
  • Add new enable_registration_token_3pid_bypass configuration option to allow registrations via token as an alternative to verifying a 3pid. (#12526)
  • Implement MSC3786: Add a default push rule to ignore m.room.server_acl events. (#12601)
  • Add new mau_appservice_trial_days configuration option to specify a different trial period for users registered via an appservice. (#12619)

Bugfixes

  • Fix a bug introduced in Synapse 1.48.0 where the latest thread reply provided failed to include the proper bundled aggregations. (#12273)
  • Fix a bug introduced in Synapse 1.22.0 where attempting to send a large amount of read receipts to an application service all at once would result in duplicate content and abnormally high memory usage. Contributed by Brad & Nick @ Beeper. (#12544)
  • Fix a bug introduced in Synapse 1.57.0 which could cause Failed to calculate hosts in room errors to be logged for outbound federation. (#12570)
  • Fix a long-standing bug where status codes would almost always get logged as 200!, irrespective of the actual status code, when clients disconnect before a request has finished processing. (#12580)
  • Fix race when persisting an event and deleting a room that could lead to outbound federation breaking. (#12594)
  • Fix a bug introduced in Synapse 1.53.0 where bundled aggregations for annotations/edits were incorrectly calculated. (#12633)
  • Fix a long-standing bug where rooms containing power levels with string values could not be upgraded. (#12657)
  • Prevent memory leak from reoccurring when presence is disabled. (#12656)

Updates to the Docker image

  • Explicitly opt-in to using BuildKit-specific features in the Dockerfile. This fixes issues with building images in some GitLab CI environments. (#12541)
  • Update the "Build docker images" GitHub Actions workflow to use docker/metadata-action to generate docker image tags, instead of a custom shell script. Contributed by @henryclw. (#12573)

Improved Documentation

  • Update SQL statements and replace use of old table user_stats_historical in docs for Synapse Admins. (#12536)
  • Add missing linebreak to pipx install instructions. (#12579)
  • Add information about the TCP replication module to docs. (#12621)
  • Fixes to the formatting of README.rst. (#12627)
  • Fix docs on how to run specific Complement tests using the complement.sh test runner. (#12664)

Deprecations and Removals

  • Remove unstable identifiers from MSC3069. (#12596)
  • Remove the unspecified m.login.jwt login type and the unstable uk.half-shot.msc2778.login.application_service from MSC2778. (#12597)
  • Synapse now requires at least Python 3.7.1 (up from 3.7.0), for compatibility with the latest Twisted trunk. (#12613)

Internal Changes

  • Use supervisord to supervise Postgres and Caddy in the Complement image to reduce restart time. (#12480)
  • Immediately retry any requests that have backed off when a server comes back online. (#12500)
  • Use make_awaitable instead of defer.succeed for return values of mocks in tests. (#12505)
  • Consistently check if an object is a frozendict. (#12564)
  • Protect module callbacks with read semantics against cancellation. (#12568)
  • Improve comments and error messages around access tokens. (#12577)
  • Improve docstrings for the receipts store. (#12581)
  • Use constants for read-receipts in tests. (#12582)
  • Log status code of cancelled requests as 499 and avoid logging stack traces for them. (#12587, #12663)
  • Remove special-case for twisted logger from default log config. (#12589)
  • Use getClientAddress instead of the deprecated getClientIP. (#12599)
  • Add link to documentation in Grafana Dashboard. (#12602)
  • Reduce log spam when running multiple event persisters. (#12610)
  • Add extra debug logging to federation sender. (#12614)
  • Prevent remote homeservers from requesting local user device names by default. (#12616)
  • Add a consistency check on events which we read from the database. (#12620)
  • Remove use of the constantly library and switch to enums for EventRedactBehaviour. Contributed by @andrewdoh. (#12624)
  • Remove unused code related to receipts. (#12632)
  • Minor improvements to the scripts for running Synapse in worker mode under Complement. (#12637)
  • Move pympler back in to the all extras. (#12652)
  • Fix spelling of M_UNRECOGNIZED in comments. (#12665)
  • Release script: confirm the commit to be tagged before tagging. (#12556)
  • Fix a typo in the announcement text generated by the Synapse release development script. (#12612)

Typechecking

  • Fix scripts-dev to pass typechecking. (#12356)
  • Add some type hints to datastore. (#12485)
  • Remove unused # type: ignores. (#12531)
  • Allow unused # type: ignore comments in bleeding edge CI jobs. (#12576)
  • Remove redundant lines of config from mypy.ini. (#12608)
  • Update to mypy 0.950. (#12650)
  • Use Concatenate to better annotate _do_execute. (#12666)
  • Use ParamSpec to refine type hints. (#12667)
  • Fix mypy against latest pillow stubs. (#12671)

Synapse 1.58.1 (2022-05-05)

This patch release includes a fix to the Debian packages, installing the systemd and cache_memory extra package groups, which were incorrectly omitted in v1.58.0. This primarily prevented Synapse from starting when the systemd.journal.JournalHandler log handler was configured. See #12631 for further information.

Otherwise, no significant changes since 1.58.0.

Synapse 1.58.0 (2022-05-03)

As of this release, the groups/communities feature in Synapse is now disabled by default. See #11584 for details. As mentioned in the upgrade notes, this feature will be removed in Synapse 1.61.

No significant changes since 1.58.0rc2.

Synapse 1.58.0rc2 (2022-04-26)

This release candidate fixes bugs related to Synapse 1.58.0rc1's logic for handling device list updates.

Bugfixes

  • Fix a bug introduced in Synapse 1.58.0rc1 where the main process could consume excessive amounts of CPU and memory while handling sentry logging failures. (#12554)
  • Fix a bug introduced in Synapse 1.58.0rc1 where opentracing contexts were not correctly sent to whitelisted remote servers with device lists updates. (#12555)

Internal Changes

  • Reduce unnecessary work when handling remote device list updates. (#12557)

Synapse 1.58.0rc1 (2022-04-26)

Features

  • Implement MSC3383 for including the destination in server-to-server authentication headers. Contributed by @Bubu and @jcgruenhage for Famedly. (#11398)
  • Docker images and Debian packages from matrix.org now contain a locked set of Python dependencies, greatly improving build reproducibility. (Board, #11537)
  • Enable processing of device list updates asynchronously. (#12365, #12465)
  • Implement MSC2815 to allow room moderators to view redacted event content. Contributed by @tulir @ Beeper. (#12427)
  • Build Debian packages for Ubuntu 22.04 "Jammy Jellyfish". (#12543)

Bugfixes

  • Prevent a sync request from removing a user's busy presence status. (#12213)
  • Fix bug with incremental sync missing events when rejoining/backfilling. Contributed by Nick @ Beeper. (#12319)
  • Fix a long-standing bug which incorrectly caused GET /_matrix/client/v3/rooms/{roomId}/event/{eventId} to return edited events rather than the original. (#12476)
  • Fix a bug introduced in Synapse 1.27.0 where the admin API for deleting forward extremities would always return a count of 1, no matter how many extremities were deleted. (#12496)
  • Fix a long-standing bug where the image thumbnails embedded into email notifications were broken. (#12510)
  • Fix a bug in the implementation of MSC3202 where Synapse would use the field name device_unused_fallback_keys, rather than device_unused_fallback_key_types. (#12520)
  • Fix a bug introduced in Synapse 0.99.3 which could cause Synapse to consume large amounts of RAM when back-paginating in a large room. (#12522)

Improved Documentation

  • Fix rendering of the documentation site when using the 'print' feature. (#12340)
  • Add a manual documenting config file options. (#12368, #12527)
  • Update documentation to reflect that both the run_background_tasks_on option and the options for moving stream writers off of the main process are no longer experimental. (#12451)
  • Update worker documentation and replace old federation_reader with generic_worker. (#12457)
  • Strongly recommend Poetry for development. (#12475)
  • Add some example configurations for workers and update architectural diagram. (#12492)
  • Fix a broken link in README.rst. (#12495)
  • Add HAProxy delegation example with CORS headers to docs. (#12501)
  • Remove extraneous comma in User Admin API's device deletion section so that the example JSON is actually valid and works. Contributed by @olmari. (#12533)

Deprecations and Removals

  • The groups/communities feature in Synapse is now disabled by default. (#12344)
  • Remove unstable identifiers from MSC3440. (#12382)

Internal Changes

  • Preparation for faster-room-join work: start a background process to resynchronise the room state after a room join. (#12394)
  • Preparation for faster-room-join work: Implement a tracking mechanism to allow functions to wait for full room state to arrive. (#12399)
  • Remove an unstable identifier from MSC3083. (#12395)
  • Run CI in the locked Poetry environment, and remove corresponding tox jobs. (#12425, #12434, #12438, #12441, #12449, #12478, #12514, #12472)
  • Change Mutual Rooms' unstable_features flag to uk.half-shot.msc2666.mutual_rooms which matches the current iteration of MSC2666. (#12445)
  • Fix typo in the release script help string. (#12450)
  • Fix a minor typo in the Debian changelogs generated by the release script. (#12497)
  • Reintroduce the list of targets to the linter script, to avoid linting unwanted local-only directories during development. (#12455)
  • Limit length of device_id to less than 512 characters. (#12454)
  • Dockerfile-workers: reduce the amount we install in the image. (#12464)
  • Dockerfile-workers: give the master its own log config. (#12466)
  • complement-synapse-workers: factor out separate entry point script. (#12467)
  • Back out experimental implementation of MSC2314. (#12474)
  • Fix grammatical error in federation error response when the room version of a room is unknown. (#12483)
  • Remove unnecessary configuration overrides in tests. (#12511)
  • Refactor the relations code for clarity. (#12519)
  • Add type hints so docker and stubs directories pass mypy --disallow-untyped-defs. (#12528)
  • Update delay_cancellation to accept any awaitable, rather than just Deferreds. (#12468)
  • Handle cancellation in EventsWorkerStore._get_events_from_cache_or_db. (#12529)

Synapse 1.57.1 (2022-04-20)

This is a patch release that only affects the Docker image. It is only of interest to administrators using the LDAP module to authenticate their users. If you have already upgraded to Synapse 1.57.0 without problem, then you have no need to upgrade to this patch release.

Updates to the Docker image

  • Include version 0.2.0 of the Synapse LDAP Auth Provider module in the Docker image. This matches the version that was present in the Docker image for Synapse v1.56.0. (#12512)

Synapse 1.57.0 (2022-04-19)

This version includes a change to the way transaction IDs are managed for application services. If your deployment uses a dedicated worker for application service traffic, it must be stopped when the database is upgraded (which normally happens when the main process is upgraded), to ensure the change is made safely without any risk of reusing transaction IDs.

See the upgrade notes for more details.

No significant changes since 1.57.0rc1.

Synapse 1.57.0rc1 (2022-04-12)

Features

  • Send device list changes to application services as specified by MSC3202, using unstable prefixes. The msc3202_transaction_extensions experimental homeserver config option must be enabled and org.matrix.msc3202: true must be present in the application service registration file for device list changes to be sent. The "left" field is currently always empty. (#11881)
  • Optimise fetching large quantities of missing room state over federation. (#12040)
  • Offload the update_client_ip background job from the main process to the background worker, when using Redis-based replication. (#12251)
  • Move update_client_ip background job from the main process to the background worker. (#12252)
  • Add a module callback to react to new 3PID (email address, phone number) associations. (#12302)
  • Add a configuration option to remove a specific set of rooms from sync responses. (#12310)
  • Add a module callback to react to account data changes. (#12327)
  • Allow setting user admin status using the module API. Contributed by Famedly. (#12341)
  • Reduce overhead of restarting synchrotrons. (#12367, #12372)
  • Update /messages to use historic pagination tokens if no from query parameter is given. (#12370)
  • Add a module API for reading and writing global account data. (#12391)
  • Support the stable v1 endpoint for /relations, per MSC2675. (#12403)
  • Include bundled aggregations in search results (MSC3666). (#12436)

Bugfixes

  • Fix a long-standing bug where updates to the server notices user profile (display name/avatar URL) in the configuration would not be applied to pre-existing rooms. Contributed by Jorge Florian. (#12115)
  • Fix a long-standing bug where events from ignored users were still considered for bundled aggregations. (#12235, #12338)
  • Fix non-member state events not resolving for historical events when used in MSC2716 /batch_send state_events_at_start. (#12329)
  • Fix a long-standing bug affecting URL previews that would generate a 500 response instead of a 403 if the previewed URL includes a port that isn't allowed by the relevant blacklist. (#12333)
  • Default to private room visibility rather than public when a client does not specify one, according to spec. (#12350)
  • Fix a spec compliance issue where requests to the /publicRooms federation API would specify limit as a string. (#12364, #12410)
  • Fix a bug introduced in Synapse 1.49.0 which caused the synapse_event_persisted_position metric to have invalid values. (#12390)

Updates to the Docker image

  • Bundle locked versions of dependencies into the Docker image. (#12385, #12439)
  • Fix up healthcheck generation for workers docker image. (#12405)

Improved Documentation

  • Clarify documentation for running SyTest against Synapse, including use of Postgres and worker mode. (#12271)
  • Document the behaviour of LoggingTransaction.call_after and LoggingTransaction.call_on_exception methods when transactions are retried. (#12315)
  • Update dead links in check-newsfragment.sh to point to the correct documentation URL. (#12331)
  • Upgrade the version of mdbook in CI to 0.4.17. (#12339)
  • Updates to the Room DAG concepts development document to clarify that we mark events as outliers because we don't have any state for them. (#12345)
  • Update the link to Redis pub/sub documentation in the workers documentation. (#12369)
  • Remove documentation for converting a legacy structured logging configuration to the new format. (#12392)

Deprecations and Removals

  • Remove the unused and unstable /aggregations endpoint which was removed from MSC2675. (#12293)

Internal Changes

  • Remove lingering unstable references to MSC2403 (knocking). (#12165)
  • Avoid trying to calculate the state at outlier events. (#12191, #12316, #12330, #12332, #12409)
  • Omit sending "offline" presence updates to application services after they are initially configured. (#12193)
  • Switch to using a sequence to generate AS transaction IDs. Contributed by Nick @ Beeper. If running synapse with a dedicated appservice worker, this MUST be stopped before upgrading the main process and database. (#12209)
  • Add missing type hints for storage. (#12267)
  • Add missing type definitions for scripts in docker folder. Contributed by Jorge Florian. (#12280)
  • Move MSC2654 support behind an experimental configuration flag. (#12295)
  • Update docstrings to explain how to decipher live and historic pagination tokens. (#12317)
  • Add ground work for speeding up device list updates for users in large numbers of rooms. (#12321)
  • Fix typechecker problems exposed by signedjson 1.1.2. (#12326)
  • Remove the tox packaging job: it will be redundant once #11537 lands. (#12334)
  • Ignore .envrc for direnv users. (#12335)
  • Remove the (broadly unused, dev-only) dockerfile for pg tests. (#12336)
  • Remove redundant get_success calls in test code. (#12346)
  • Add type annotations for tests/unittest.py. (#12347)
  • Move single-use methods out of TestCase. (#12348)
  • Remove broken and unused development scripts. (#12349, #12351, #12355)
  • Convert Linearizer tests from inlineCallbacks to async. (#12353)
  • Update docstrings for ReadWriteLock tests. (#12354)
  • Refactor Linearizer, convert methods to async and use an async context manager. (#12357)
  • Fix a long-standing bug where Linearizers could get stuck if a cancellation were to happen at the wrong time. (#12358)
  • Make StreamToken.from_string and RoomStreamToken.parse propagate cancellations instead of replacing them with SynapseErrors. (#12366)
  • Add type hints to tests files. (#12371)
  • Allow specifying the Postgres database's port when running unit tests with Postgres. (#12376)
  • Remove temporary pin of signedjson<=1.1.1 that was added in Synapse 1.56.0. (#12379)
  • Add opentracing spans to calls to external cache. (#12380)
  • Lay groundwork for using poetry to manage Synapse's dependencies. (#12381, #12407, #12412, #12418)
  • Make missing importlib_metadata dependency explicit. (#12384, #12400)
  • Update type annotations for compatiblity with prometheus_client 0.14. (#12389)
  • Remove support for the unstable identifiers specified in MSC3288. (#12398)
  • Add missing type hints to configuration classes. (#12402)
  • Add files used to build the Docker image used for complement testing into the Synapse repository. (#12404)
  • Do not include groups in the sync response when disabled. (#12408)
  • Improve type hints related to HTTP query parameters. (#12415)
  • Stop maintaining a list of lint targets. (#12420)
  • Make synapse._scripts pass type checks. (#12421, #12422)
  • Add some type hints to datastore. (#12423)
  • Enable certificate checking during complement tests. (#12435)
  • Explicitly specify the tls extra for Twisted dependency. (#12444)

Synapse 1.56.0 (2022-04-05)

Synapse will now refuse to start up if open registration is enabled, in order to help mitigate abuse across the federation. If you would like to provide registration to anyone, consider adding email, recaptcha or token-based verification in order to prevent automated registration from bad actors. This check can be disabled by setting the enable_registration_without_verification option in your homeserver configuration file to true. More details are available in the upgrade notes.

Synapse will additionally now refuse to start when using PostgreSQL with a non-C values for COLLATE and CTYPE, unless the config flag allow_unsafe_locale, found in the database section of the configuration file, is set to true. See the upgrade notes for details.

Internal Changes

  • Bump the version of black for compatibility with the latest click release. (#12320)

Synapse 1.56.0rc1 (2022-03-29)

Features

  • Allow modules to store already existing 3PID associations. (#12195)
  • Allow registering server administrators using the module API. Contributed by Famedly. (#12250)

Bugfixes

  • Fix a long-standing bug which caused the /_matrix/federation/v1/state and /_matrix/federation/v1/state_ids endpoints to return incorrect or invalid data when called for an event which we have stored as an "outlier". (#12087)
  • Fix a long-standing bug where events from ignored users would still be considered for relations. (#12227, #12232, #12285)
  • Fix a bug introduced in Synapse 1.53.0 where an unnecessary query could be performed when fetching bundled aggregations for threads. (#12228)
  • Fix a bug introduced in Synapse 1.52.0 where admins could not deactivate and GDPR-erase a user if Synapse was configured with limits on avatars. (#12261)

Improved Documentation

  • Fix the link to the module documentation in the legacy spam checker warning message. (#12231)
  • Remove incorrect prefixes in the worker documentation for some endpoints. (#12243)
  • Correct check_username_for_spam annotations and docs. (#12246)
  • Correct Authentik OpenID typo, and add notes on troubleshooting. Contributed by @IronTooch. (#12275)
  • HAProxy reverse proxy guide update to stop sending IPv4-mapped address to homeserver. Contributed by @villepeh. (#12279)

Internal Changes

  • Rename shared_rooms to mutual_rooms (MSC2666), as per proposal changes. (#12036)
  • Remove check on update_user_directory for shared rooms handler (MSC2666), and update/expand documentation. (#12038)
  • Refactor create_new_client_event to use a new parameter, state_event_ids, which accurately describes the usage with MSC2716 instead of abusing auth_event_ids. (#12083, #12304)
  • Refuse to start if registration is enabled without email, captcha, or token-based verification unless the new config flag enable_registration_without_verification is set to true. (#12091, #12322)
  • Add tests for database transaction callbacks. (#12198)
  • Handle cancellation in DatabasePool.runInteraction. (#12199)
  • Add missing type hints for cache storage. (#12216)
  • Add missing type hints for storage. (#12248, #12255)
  • Add type hints to tests files. (#12224, #12240, #12256)
  • Use type stubs for psycopg2. (#12269)
  • Improve type annotations for execute_values. (#12311)
  • Clean-up logic around rebasing URLs for URL image previews. (#12219)
  • Use the ignored_users table in additional places instead of re-parsing the account data. (#12225)
  • Refactor the relations endpoints to add a RelationsHandler. (#12237)
  • Generate announcement links in the release script. (#12242)
  • Improve error message when dependencies check finds a broken installation. (#12244)
  • Compress metrics HTTP resource when enabled. Contributed by Nick @ Beeper. (#12258)
  • Refuse to start if the PostgreSQL database has a non-C locale, unless the config flag allow_unsafe_db_locale is set to true. (#12262, #12288)
  • Optionally include account validity expiration information to experimental MSC3720 account status responses. (#12266)
  • Add a new cache _get_membership_from_event_id to speed up push rule calculations in large rooms. (#12272)
  • Re-enable Complement concurrency in CI. (#12283)
  • Remove unused test utilities. (#12291)
  • Enhance logging for inbound federation events. (#12301)
  • Fix compatibility with the recently-released Jinja 3.1. (#12313)
  • Avoid trying to calculate the state at outlier events. (#12314)

Synapse 1.55.2 (2022-03-24)

This patch version reverts the earlier fixes from Synapse 1.55.1, which could cause problems in certain deployments, and instead adds a cap to the version of Jinja to be installed. Again, this is to fix an incompatibility with version 3.1.0 of the Jinja library, and again, deployments of Synapse using the matrixdotorg/synapse Docker image or Debian packages from packages.matrix.org are not affected.

Internal Changes

  • Pin Jinja to <3.1.0, as Synapse fails to start with Jinja 3.1.0. (#12297)
  • Revert changes from 1.55.1 as they caused problems with older versions of Jinja (#12296)

Synapse 1.55.1 (2022-03-24)

This is a patch release that fixes an incompatibility with version 3.1.0 of the Jinja library, released on March 24th, 2022. Deployments of Synapse using the matrixdotorg/synapse Docker image or Debian packages from packages.matrix.org are not affected.

Internal Changes

  • Remove uses of the long-deprecated jinja2.Markup which would prevent Synapse from starting with Jinja 3.1.0 or above installed. (#12289)

Synapse 1.55.0 (2022-03-22)

This release removes a workaround introduced in Synapse 1.50.0 for Mjolnir compatibility. This breaks compatibility with Mjolnir 1.3.1 and earlier. (#11700); Mjolnir users should upgrade Mjolnir before upgrading Synapse to this version.

This release also moves the location of the synctl script; see the upgrade notes for more details.

Internal Changes

  • Tweak copy for default Single Sign-On account details template to better adhere to mobile app store guidelines. (#12265, #12260)

Synapse 1.55.0rc1 (2022-03-15)

Features

  • Add third-party rules callbacks check_can_shutdown_room and check_can_deactivate_user. (#12028)
  • Improve performance of logging in for large accounts. (#12132)
  • Add experimental env var SYNAPSE_ASYNC_IO_REACTOR that causes Synapse to use the asyncio reactor for Twisted. (#12135)
  • Support the stable identifiers from MSC3440: threads. (#12151)
  • Add a new Jinja2 template filter to extract the local part of an email address. (#12212)

Bugfixes

  • Use the proper serialization format for bundled thread aggregations. The bug has existed since Synapse v1.48.0. (#12090)
  • Fix a long-standing bug when redacting events with relations. (#12113, #12121, #12130, #12189)
  • Fix a bug introduced in Synapse 1.7.2 whereby background updates are never run with the default background batch size. (#12157)
  • Fix a bug where non-standard information was returned from the /hierarchy API. Introduced in Synapse v1.41.0. (#12175)
  • Fix a bug introduced in Synapse 1.54.0 that broke background updates on sqlite homeservers while search was disabled. (#12215)
  • Fix a long-standing bug when a filter argument with event_fields which did not include the unsigned field could result in a 500 error on /sync. (#12234)

Improved Documentation

  • Fix complexity checking config example in Resource Constrained Devices docs page. (#11998)
  • Improve documentation for demo scripts. (#12143)
  • Updates to the Room DAG concepts development document. (#12179)
  • Document that the typing, to_device, account_data, receipts, and presence stream writer can only be used on a single worker. (#12196)
  • Document that contributors can sign off privately by email. (#12204)

Deprecations and Removals

  • Remove workaround introduced in Synapse 1.50.0 for Mjolnir compatibility. Breaks compatibility with Mjolnir 1.3.1 and earlier. (#11700)
  • **synctl has been moved into into synapse._scripts and is exposed as an entry point; see upgrade notes. (#12140)
  • Remove backwards compatibilty with pagination tokens from the /relations and /aggregations endpoints generated from Synapse < v1.52.0. (#12138)
  • The groups/communities feature in Synapse has been deprecated. (#12200)

Internal Changes

  • Simplify the ApplicationService class' set of public methods related to interest checking. (#11915)
  • Add config settings for background update parameters. (#11980)
  • Correct type hints for txredis. (#12042)
  • Limit the size of aggregation_key on annotations. (#12101)
  • Add type hints to tests files. (#12108, #12146, #12207, #12208)
  • Move scripts to Synapse package and expose as setuptools entry points. (#12118)
  • Add support for cancellation to ReadWriteLock. (#12120)
  • Fix data validation to compare to lists, not sequences. (#12128)
  • Fix CI not attaching source distributions and wheels to the GitHub releases. (#12131)
  • Remove unused mocks from test_typing. (#12136)
  • Give scripts-dev scripts suffixes for neater CI config. (#12137)
  • Move the snapcraft configuration file to contrib. (#12142)
  • Enable MSC3030 Complement tests in CI. (#12144)
  • Enable MSC2716 Complement tests in CI. (#12145)
  • Add test for ObservableDeferred's cancellation behaviour. (#12149)
  • Use ParamSpec in type hints for synapse.logging.context. (#12150)
  • Prune unused jobs from tox config. (#12152)
  • Move CI checks out of tox, to facilitate a move to using poetry. (#12153)
  • Avoid generating state groups for local out-of-band leaves. (#12154)
  • Avoid trying to calculate the state at outlier events. (#12155, #12173, #12202)
  • Fix some type annotations. (#12156)
  • Add type hints for ObservableDeferred attributes. (#12159)
  • Use a prebuilt Action for the tests-done CI job. (#12161)
  • Reduce number of DB queries made during processing of /sync. (#12163)
  • Add delay_cancellation utility function, which behaves like stop_cancellation but waits until the original Deferred resolves before raising a CancelledError. (#12180)
  • Retry HTTP replication failures, this should prevent 502's when restarting stateful workers (main, event persisters, stream writers). Contributed by Nick @ Beeper. (#12182)
  • Add cancellation support to @cached and @cachedList decorators. (#12183)
  • Remove unused variables. (#12187)
  • Add combined test for HTTP pusher and push rule. Contributed by Nick @ Beeper. (#12188)
  • Rename HomeServer.get_tcp_replication to get_replication_command_handler. (#12192)
  • Remove some dead code. (#12197)
  • Fix a misleading comment in the function check_event_for_spam. (#12203)
  • Remove unnecessary pass statements. (#12206)
  • Update the SSO username picker template to comply with SIWA guidelines. (#12210)
  • Improve code documentation for the typing stream over replication. (#12211)

Synapse 1.54.0 (2022-03-08)

Please note that this will be the last release of Synapse that is compatible with Mjolnir 1.3.1 and earlier. Administrators of servers which have the Mjolnir module installed are advised to upgrade Mjolnir to version 1.3.2 or later.

Bugfixes

  • Fix a bug introduced in Synapse 1.54.0rc1 preventing the new module callbacks introduced in this release from being registered by modules. (#12141)
  • Fix a bug introduced in Synapse 1.54.0rc1 where runtime dependency version checks would mistakenly check development dependencies if they were present and would not accept pre-release versions of dependencies. (#12129, #12177)

Internal Changes

  • Update release script to insert the previous version when writing "No significant changes" line in the changelog. (#12127)
  • Relax the version guard for "packaging" added in #12088. (#12166)

Synapse 1.54.0rc1 (2022-03-02)

Features

  • Add support for MSC3202: sending one-time key counts and fallback key usage states to Application Services. (#11617)
  • Improve the generated URL previews for some web pages. Contributed by @AndrewRyanChama. (#11985)
  • Track cache invalidations in Prometheus metrics, as already happens for cache eviction based on size or time. (#12000)
  • Implement experimental support for MSC3720 (account status endpoints). (#12001, #12067)
  • Enable modules to set a custom display name when registering a user. (#12009)
  • Advertise Matrix 1.1 and 1.2 support on /_matrix/client/versions. (#12020, (#12022)
  • Support only the stable identifier for MSC3069's is_guest on /_matrix/client/v3/account/whoami. (#12021)
  • Use room version 9 as the default room version (per MSC3589). (#12058)
  • Add module callbacks to react to user deactivation status changes (i.e. deactivations and reactivations) and profile updates. (#12062)

Bugfixes

  • Fix a bug introduced in Synapse 1.48.0 where an edit of the latest event in a thread would not be properly applied to the thread summary. (#11992)
  • Fix long-standing bug where the get_rooms_for_user cache was not correctly invalidated for remote users when the server left a room. (#11999)
  • Fix a 500 error with Postgres when looking backwards with the MSC3030 /timestamp_to_event?dir=b endpoint. (#12024)
  • Properly fix a long-standing bug where wrong data could be inserted into the event_search table when using SQLite. This could block running synapse_port_db with an argument of type 'int' is not iterable error. This bug was partially fixed by a change in Synapse 1.44.0. (#12037)
  • Fix slow performance of /logout in some cases where refresh tokens are in use. The slowness existed since the initial implementation of refresh tokens in version 1.38.0. (#12056)
  • Fix a long-standing bug where Synapse would make additional failing requests over federation for missing data. (#12077)
  • Fix occasional Unhandled error in Deferred error message. (#12089)
  • Fix a bug introduced in Synapse 1.51.0 where incoming federation transactions containing at least one EDU would be dropped if debug logging was enabled for synapse.8631_debug. (#12098)
  • Fix a long-standing bug which could cause push notifications to malfunction if use_frozen_dicts was set in the configuration. (#12100)
  • Fix an extremely rare, long-standing bug in ReadWriteLock that would cause an error when a newly unblocked writer completes instantly. (#12105)
  • Make a POST to /rooms/<room_id>/receipt/m.read/<event_id> only trigger a push notification if the count of unread messages is different to the one in the last successfully sent push. This reduces server load and load on the receiving device. (#11835)

Updates to the Docker image

  • The Docker image no longer automatically creates a temporary volume at /data. This is not expected to affect normal usage. (#11997)
  • Use Python 3.9 in Docker images by default. (#12112)

Improved Documentation

  • Document support for the to_device, account_data, receipts, and presence stream writers for workers. (#11599)
  • Explain the meaning of spam checker callbacks' return values. (#12003)
  • Clarify information about external Identity Provider IDs. (#12004)

Deprecations and Removals

  • Deprecate using synctl with the config option synctl_cache_factor and print a warning if a user still uses this option. (#11865)
  • Remove support for the legacy structured logging configuration (please see the the upgrade notes if you are using structured: true in the Synapse configuration). (#12008)
  • Drop support for MSC3283 unstable flags now that the stable flags are supported. (#12018)
  • Remove the unstable /spaces endpoint from MSC2946. (#12073)

Internal Changes

  • Make the get_room_version method use get_room_version_id to benefit from caching. (#11808)
  • Remove unnecessary condition on knock -> leave auth rule check. (#11900)
  • Add tests for device list changes between local users. (#11972)
  • Optimise calculating device_list changes in /sync. (#11974)
  • Add missing type hints to storage classes. (#11984)
  • Refactor the search code for improved readability. (#11991)
  • Move common deduplication code down into _auth_and_persist_outliers. (#11994)
  • Limit concurrent joins from applications services. (#11996)
  • Preparation for faster-room-join work: when parsing the send_join response, get the m.room.create event from state, not auth_chain. (#12005, #12039)
  • Preparation for faster-room-join work: parse MSC3706 fields in send_join response. (#12011)
  • Preparation for faster-room-join work: persist information on which events and rooms have partial state to the database. (#12012)
  • Preparation for faster-room-join work: Support for calling /federation/v1/state on a remote server. (#12013)
  • Configure tox to use venv rather than virtualenv. (#12015)
  • Fix bug in StateFilter.return_expanded() and add some tests. (#12016)
  • Use Matrix v1.1 endpoints (/_matrix/client/v3/auth/...) in fallback auth HTML forms. (#12019)
  • Update the olddeps CI job to use an old version of markupsafe. (#12025)
  • Upgrade Mypy to version 0.931. (#12030)
  • Remove legacy HomeServer.get_datastore(). (#12031, #12070)
  • Minor typing fixes. (#12034, #12069)
  • After joining a room, create a dedicated logcontext to process the queued events. (#12041)
  • Tidy up GitHub Actions config which builds distributions for PyPI. (#12051)
  • Move configuration out of setup.cfg. (#12052, #12059)
  • Fix error message when a worker process fails to talk to another worker process. (#12060)
  • Fix using the complement.sh script without specifying a directory or a branch. Contributed by Nico on behalf of Famedly. (#12063)
  • Add type hints to tests/rest/client. (#12066, #12072, #12084, #12094)
  • Add some logging to /sync to try and track down #11916. (#12068)
  • Inspect application dependencies using importlib.metadata or its backport. (#12088)
  • Use assertEqual instead of the deprecated assertEquals in test code. (#12092)
  • Move experimental support for MSC3440 to /versions. (#12099)
  • Add stop_cancellation utility function to stop Deferreds from being cancelled. (#12106)
  • Improve exception handling for concurrent execution. (#12109)
  • Advertise support for Python 3.10 in packaging files. (#12111)
  • Move CI checks out of tox, to facilitate a move to using poetry. (#12119)

Synapse 1.53.0 (2022-02-22)

No significant changes since 1.53.0rc1.

Synapse 1.53.0rc1 (2022-02-15)

Features

  • Add experimental support for sending to-device messages to application services, as specified by MSC2409. (#11215, #11966)
  • Add a background database update to purge account data for deactivated users. (#11655)
  • Experimental support for MSC3666: including bundled aggregations in server side search results. (#11837)
  • Enable cache time-based expiry by default. The expiry_time config flag has been superseded by expire_caches and cache_entry_ttl. (#11849)
  • Add a callback to allow modules to allow or forbid a 3PID (email address, phone number) from being associated to a local account. (#11854)
  • Stabilize support and remove unstable endpoints for MSC3231. Clients must switch to the stable identifier and endpoint. See the upgrade notes for more information. (#11867)
  • Allow modules to retrieve the current instance's server name and worker name. (#11868)
  • Use a dedicated configurable rate limiter for 3PID invites. (#11892)
  • Support the stable API endpoint for MSC3283: new settings in /capabilities endpoint. (#11933, #11989)
  • Support the dir parameter on the /relations endpoint, per MSC3715. (#11941)
  • Experimental implementation of MSC3706: extensions to /send_join to support reduced response size. (#11967)

Bugfixes

  • Fix MSC2716 historical messages backfilling in random order on remote homeservers. (#11114)
  • Fix a bug introduced in Synapse 1.51.0 where incoming federation transactions containing at least one EDU would be dropped if debug logging was enabled for synapse.8631_debug. (#11890)
  • Fix a long-standing bug where some unknown endpoints would return HTML error pages instead of JSON M_UNRECOGNIZED errors. (#11930)
  • Implement an allow list of content types for which we will attempt to preview a URL. This prevents Synapse from making useless longer-lived connections to streaming media servers. (#11936)
  • Fix a long-standing bug where pagination tokens from /sync and /messages could not be provided to the /relations API. (#11952)
  • Require that modules register their callbacks using keyword arguments. (#11975)
  • Fix a long-standing bug where M_WRONG_ROOM_KEYS_VERSION errors would not include the specced current_version field. (#11988)

Improved Documentation

  • Fix typo in User Admin API: unpind -> unbind. (#11859)
  • Document images returned by the User List Media Admin API can include those generated by URL previews. (#11862)
  • Remove outdated MSC1711 FAQ document. (#11907)
  • Correct the structured logging configuration example. Contributed by Brad Jones. (#11946)
  • Add information on the Synapse release cycle. (#11954)
  • Fix broken link in the README to the admin API for password reset. (#11955)

Deprecations and Removals

  • Drop support for webclient listeners and configuring web_client_location to a non-HTTP(S) URL. Deprecated configurations are a configuration error. (#11895)
  • Remove deprecated user_may_create_room_with_invites spam checker callback. See the upgrade notes for more information. (#11950)
  • No longer build .deb packages for Ubuntu 21.04 Hirsute Hippo, which has now EOLed. (#11961)

Internal Changes

  • Enhance user registration test helpers to make them more useful for tests involving application services and devices. (#11615, #11616)
  • Improve performance when fetching bundled aggregations for multiple events. (#11660, #11752)
  • Fix type errors introduced by new annotations in the Prometheus Client library. (#11832)
  • Add missing type hints to replication code. (#11856, #11938)
  • Ensure that opentracing scopes are activated and closed at the right time. (#11869)
  • Improve opentracing for incoming federation requests. (#11870)
  • Improve internal docstrings in synapse.util.caches. (#11876)
  • Do not needlessly clear the get_users_in_room and get_users_in_room_with_profiles caches when any room state changes. (#11878)
  • Convert ApplicationServiceTestCase to use simple_async_mock. (#11880)
  • Remove experimental changes to the default push rules which were introduced in Synapse 1.19.0 but never enabled. (#11884)
  • Disable coverage calculation for olddeps build. (#11888)
  • Preparation to support sending device list updates to application services. (#11905)
  • Add a test that checks users receive their own device list updates down /sync. (#11909)
  • Run Complement tests sequentially. (#11910)
  • Various refactors to the application service notifier code. (#11911, #11912)
  • Tests: replace mocked Authenticator with the real thing. (#11913)
  • Various refactors to the typing notifications code. (#11914)
  • Use the proper type for the Content-Length header in the UploadResource. (#11927)
  • Remove an unnecessary ignoring of type hints due to fixes in upstream packages. (#11939)
  • Add missing type hints. (#11953)
  • Fix an import cycle in synapse.event_auth. (#11965)
  • Unpin frozendict but exclude the known bad version 2.1.2. (#11969)
  • Prepare for rename of default Complement branch. (#11971)
  • Fetch Synapse's version using a helper from matrix-common. (#11979)

Synapse 1.52.0 (2022-02-08)

No significant changes since 1.52.0rc1.

Note that Twisted 22.1.0 has recently been released, which fixes a security issue within the Twisted library. We do not believe Synapse is affected by this vulnerability, though we advise server administrators who installed Synapse via pip to upgrade Twisted with pip install --upgrade Twisted treq as a matter of good practice. The Docker image matrixdotorg/synapse and the Debian packages from packages.matrix.org are using the updated library.

Synapse 1.52.0rc1 (2022-02-01)

Features

  • Remove account data (including client config, push rules and ignored users) upon user deactivation. (#11621, #11788, #11789)
  • Add an admin API to reset connection timeouts for remote server. (#11639)
  • Add an admin API to get a list of rooms that federate with a given remote homeserver. (#11658)
  • Add a config flag to inhibit M_USER_IN_USE during registration. (#11743)
  • Add a module callback to set username at registration. (#11790)
  • Allow configuring a maximum file size as well as a list of allowed content types for avatars. (#11846)

Bugfixes

  • Include the bundled aggregations in the /sync response, per MSC2675. (#11612)
  • Fix a long-standing bug when previewing Reddit URLs which do not contain an image. (#11767)
  • Fix a long-standing bug that media streams could cause long-lived connections when generating URL previews. (#11784)
  • Include a prev_content field in state events sent to Application Services. Contributed by @totallynotvaishnav. (#11798)
  • Fix a bug introduced in Synapse 0.33.3 causing requests to sometimes log strings such as HTTPStatus.OK instead of integer status codes. (#11827)

Improved Documentation

  • Update pypi installation docs to indicate that we now support Python 3.10. (#11820)
  • Add missing steps to the contribution submission process in the documentation. Contributed by @sequentialread. (#11821)
  • Remove not needed old table of contents in documentation. (#11860)
  • Consolidate the access_token information at the top of each relevant page in the Admin API documentation. (#11861)

Deprecations and Removals

  • Drop support for Python 3.6, which is EOL. (#11683)
  • Remove the experimental_msc1849_support_enabled flag as the features are now stable. (#11843)

Internal Changes

  • Preparation for database schema simplifications: add state_key and rejection_reason columns to events table. (#11792)
  • Add FrozenEvent.get_state_key and use it in a couple of places. (#11793)
  • Preparation for database schema simplifications: stop reading from event_reference_hashes. (#11794)
  • Drop unused table public_room_list_stream. (#11795)
  • Preparation for reducing Postgres serialization errors: allow setting transaction isolation level. Contributed by Nick @ Beeper. (#11799, #11847)
  • Docker: skip the initial amd64-only build and go straight to multiarch. (#11810)
  • Run Complement on the Github Actions VM and not inside a Docker container. (#11811)
  • Log module names at startup. (#11813)
  • Improve type safety of bundled aggregations code. (#11815)
  • Correct a type annotation in the event validation logic. (#11817, #11830)
  • Minor updates and documentation for database schema delta files. (#11823)
  • Workaround a type annotation problem in prometheus_client 0.13.0. (#11834)
  • Minor performance improvement in room state lookup. (#11836)
  • Fix some indentation inconsistencies in the sample config. (#11838)
  • Add type hints to tests/rest/admin. (#11851)

Synapse 1.51.0 (2022-01-25)

No significant changes since 1.51.0rc2.

Synapse 1.51.0 deprecates webclient listeners and non-HTTP(S) web_client_locations. Support for these will be removed in Synapse 1.53.0, at which point Synapse will not be capable of directly serving a web client for Matrix. See the upgrade notes.

Synapse 1.51.0rc2 (2022-01-24)

Bugfixes

  • Fix a bug introduced in Synapse 1.40.0 that caused Synapse to fail to process incoming federation traffic after handling a large amount of events in a v1 room. (#11806)

Synapse 1.50.2 (2022-01-24)

This release includes the same bugfix as Synapse 1.51.0rc2.

Bugfixes

  • Fix a bug introduced in Synapse 1.40.0 that caused Synapse to fail to process incoming federation traffic after handling a large amount of events in a v1 room. (#11806)

Synapse 1.51.0rc1 (2022-01-21)

Features

  • Add track_puppeted_user_ips config flag to record client IP addresses against puppeted users, and include the puppeted users in monthly active user counts. (#11561, #11749, #11757)
  • Include whether the requesting user has participated in a thread when generating a summary for MSC3440. (#11577)
  • Return an M_FORBIDDEN error code instead of M_UNKNOWN when a spam checker module prevents a user from creating a room. (#11672)
  • Add a flag to the synapse_review_recent_signups script to ignore and filter appservice users. (#11675, #11770)

Bugfixes

  • Fix a long-standing issue which could cause Synapse to incorrectly accept data in the unsigned field of events received over federation. (#11530)
  • Fix a long-standing bug where Synapse wouldn't cache a response indicating that a remote user has no devices. (#11587)
  • Fix an error that occurs whilst trying to get the federation status of a destination server that was working normally. This admin API was newly introduced in Synapse v1.49.0. (#11593)
  • Fix bundled aggregations not being included in the /sync response, per MSC2675. (#11612, #11659, #11791)
  • Fix the /_matrix/client/v1/room/{roomId}/hierarchy endpoint returning incorrect fields which have been present since Synapse 1.49.0. (#11667)
  • Fix preview of some GIF URLs (like tenor.com). Contributed by Philippe Daouadi. (#11669)
  • Fix a bug where only the first 50 rooms from a space were returned from the /hierarchy API. This has existed since the introduction of the API in Synapse v1.41.0. (#11695)
  • Fix a bug introduced in Synapse v1.18.0 where password reset and address validation emails would not be sent if their subject was configured to use the 'app' template variable. Contributed by @br4nnigan. (#11710, #11745)
  • Make the 'List Rooms' Admin API sort stable. Contributed by Daniël Sonck. (#11737)
  • Fix a long-standing bug where space hierarchy over federation would only work correctly some of the time. (#11775)
  • Fix a bug introduced in Synapse v1.46.0 that prevented on_logged_out module callbacks from being correctly awaited by Synapse. (#11786)

Improved Documentation

  • Warn against using a Let's Encrypt certificate for TLS/DTLS TURN server client connections, and suggest using ZeroSSL certificate instead. This works around client-side connectivity errors caused by WebRTC libraries that reject Let's Encrypt certificates. Contibuted by @AndrewFerr. (#11686)
  • Document the new SYNAPSE_TEST_PERSIST_SQLITE_DB environment variable in the contributing guide. (#11715)
  • Document that the minimum supported PostgreSQL version is now 10. (#11725)
  • Fix typo in demo docs: differnt. (#11735)
  • Update room spec URL in config files. (#11739)
  • Mention python3-venv and libpq-dev dependencies in the contribution guide. (#11740)
  • Update documentation for configuring login with Facebook. (#11755)
  • Update installation instructions to note that Python 3.6 is no longer supported. (#11781)

Deprecations and Removals

  • Remove the unstable /send_relation endpoint. (#11682)
  • Remove python_twisted_reactor_pending_calls Prometheus metric. (#11724)
  • Remove the password_hash field from the response dictionaries of the Users Admin API. (#11576)
  • Deprecate support for webclient listeners and non-HTTP(S) web_client_location configuration. (#11774, #11783)

Internal Changes

  • Run pyupgrade --py37-plus --keep-percent-format on Synapse. (#11685)
  • Use buildkit's cache feature to speed up docker builds. (#11691)
  • Use auto_attribs and native type hints for attrs classes. (#11692, #11768)
  • Remove debug logging for #4422, which has been closed since Synapse 0.99. (#11693)
  • Remove fallback code for Python 2. (#11699)
  • Add a test for an edge case in the /sync logic. (#11701)
  • Add the option to write SQLite test dbs to disk when running tests. (#11702)
  • Improve Complement test output for Gitub Actions. (#11707)
  • Fix docstring on add_account_data_for_user. (#11716)
  • Complement environment variable name change and update .gitignore. (#11718)
  • Simplify calculation of Prometheus metrics for garbage collection. (#11723)
  • Improve accuracy of python_twisted_reactor_tick_time Prometheus metric. (#11724, #11771)
  • Minor efficiency improvements when inserting many values into the database. (#11742)
  • Invite PR authors to give themselves credit in the changelog. (#11744)
  • Add optional debugging to investigate issue 8631. (#11760)
  • Remove log_function utility function and its uses. (#11761)
  • Add a unit test that checks both client and webclient resources will function when simultaneously enabled. (#11765)
  • Allow overriding complement commit using COMPLEMENT_REF. (#11766)
  • Add some comments and type annotations for _update_outliers_txn. (#11776)

Synapse 1.50.1 (2022-01-18)

This release fixes a bug in Synapse 1.50.0 that could prevent clients from being able to connect to Synapse if the webclient resource was enabled. Further details are available in this issue.

Bugfixes

  • Fix a bug introduced in Synapse 1.50.0rc1 that could cause Matrix clients to be unable to connect to Synapse instances with the webclient resource enabled. (#11764)

Synapse 1.50.0 (2022-01-18)

This release contains a critical bug that may prevent clients from being able to connect. As such, it is not recommended to upgrade to 1.50.0. Instead, please upgrade straight to to 1.50.1. Further details are available in this issue.

Please note that we now only support Python 3.7+ and PostgreSQL 10+ (if applicable), because Python 3.6 and PostgreSQL 9.6 have reached end-of-life.

No significant changes since 1.50.0rc2.

Synapse 1.50.0rc2 (2022-01-14)

This release candidate fixes a federation-breaking regression introduced in Synapse 1.50.0rc1.

Bugfixes

  • Fix a bug introduced in Synapse v1.0.0 whereby some device list updates would not be sent to remote homeservers if there were too many to send at once. (#11729)
  • Fix a bug introduced in Synapse v1.50.0rc1 whereby outbound federation could fail because too many EDUs were produced for device updates. (#11730)

Improved Documentation

  • Document that now the minimum supported PostgreSQL version is 10. (#11725)

Internal Changes

  • Fix a typechecker problem related to our (ab)use of nacl.signing.SigningKeys. (#11714)

Synapse 1.50.0rc1 (2022-01-05)

Features

  • Allow guests to send state events per MSC3419. (#11378)
  • Add experimental support for part of MSC3202: allowing application services to masquerade as specific devices. (#11538)
  • Add admin API to get users' account data. (#11664)
  • Include the room topic in the stripped state included with invites and knocking. (#11666)
  • Send and handle cross-signing messages using the stable prefix. (#10520)
  • Support unprefixed versions of fallback key property names. (#11541)

Bugfixes

  • Fix a long-standing bug where relations from other rooms could be included in the bundled aggregations of an event. (#11516)
  • Fix a long-standing bug which could cause AssertionErrors to be written to the log when Synapse was restarted after purging events from the database. (#11536, #11642)
  • Fix a bug introduced in Synapse 1.17.0 where a pusher created for an email with capital letters would fail to be created. (#11547)
  • Fix a long-standing bug where responses included bundled aggregations when they should not, per MSC2675. (#11592, #11623)
  • Fix a long-standing bug that some unknown endpoints would return HTML error pages instead of JSON M_UNRECOGNIZED errors. (#11602)
  • Fix a bug introduced in Synapse 1.19.3 which could sometimes cause AssertionErrors when backfilling rooms over federation. (#11632)

Improved Documentation

  • Update Synapse install command for FreeBSD as the package is now prefixed with py38. Contributed by @itchychips. (#11267)
  • Document the usage of refresh tokens. (#11427)
  • Add details for how to configure a TURN server when behind a NAT. Contibuted by @AndrewFerr. (#11553)
  • Add references for using Postgres to the Docker documentation. (#11640)
  • Fix the documentation link in newly-generated configuration files. (#11678)
  • Correct the documentation for nginx to use a case-sensitive url pattern. Fixes an error introduced in v1.21.0. (#11680)
  • Clarify SSO mapping provider documentation by writing def or async def before the names of methods, as appropriate. (#11681)

Deprecations and Removals

  • Replace mock package by its standard library version. (#11588)
  • Drop support for Python 3.6 and Ubuntu 18.04. (#11633)

Internal Changes

  • Allow specific, experimental events to be created without prev_events. Used by MSC2716. (#11243)
  • A test helper (wait_for_background_updates) no longer depends on classes defining a store property. (#11331)
  • Add type hints to synapse.appservice. (#11360)
  • Add missing type hints to synapse.config module. (#11480)
  • Add test to ensure we share the same state_group across the whole historical batch when using the MSC2716 /batch_send endpoint. (#11487)
  • Refactor tests.util.setup_test_homeserver and tests.server.setup_test_homeserver. (#11503)
  • Move glob_to_regex and re_word_boundary to matrix-python-common. (#11505, #11687)
  • Use HTTPStatus constants in place of literals in tests.rest.client.test_auth. (#11520)
  • Add a receipt types constant for m.read. (#11531)
  • Clean up synapse.rest.admin. (#11535)
  • Add missing errcode to parse_string and parse_boolean. (#11542)
  • Use HTTPStatus constants in place of literals in synapse.http. (#11543)
  • Add missing type hints to storage classes. (#11546, #11549, #11551, #11555, #11575, #11589, #11594, #11652, #11653, #11654, #11657)
  • Fix an inaccurate and misleading comment in the /sync code. (#11550)
  • Add missing type hints to synapse.logging.context. (#11556)
  • Stop populating unused database column state_events.prev_state. (#11558)
  • Minor efficiency improvements in event persistence. (#11560)
  • Add some safety checks that storage functions are used correctly. (#11564, #11580)
  • Make get_device return None if the device doesn't exist rather than raising an exception. (#11565)
  • Split the HTML parsing code from the URL preview resource code. (#11566)
  • Remove redundant COALESCE()s around COUNT()s in database queries. (#11570)
  • Add missing type hints to synapse.http. (#11571)
  • Add MSC2716 and MSC3030 to /versions -> unstable_features to detect server support. (#11582)
  • Add type hints to synapse/tests/rest/admin. (#11590)
  • Drop end-of-life Python 3.6 and Postgres 9.6 from CI. (#11595)
  • Update black version and run it on all the files. (#11596)
  • Add opentracing type stubs and fix associated mypy errors. (#11603, #11622)
  • Improve OpenTracing support for requests which use a ResponseCache. (#11607)
  • Improve OpenTracing support for incoming HTTP requests. (#11618)
  • A number of improvements to opentracing support. (#11619)
  • Refactor the way that the outlier flag is set on events received over federation. (#11634)
  • Improve the error messages from get_create_event_for_room. (#11638)
  • Remove redundant get_current_events_token method. (#11643)
  • Convert namedtuples to attrs. (#11665, #11574)
  • Update the /capabilities response to include whether support for MSC3440 is available. (#11690)
  • Send the Accept header in HTTP requests made using SimpleHttpClient.get_json. (#11677)
  • Work around Mjolnir compatibility issue by adding an import for glob_to_regex in synapse.util, where it moved from. (#11696)

Changelogs for older versions can be found here.