542 KiB
Synapse 1.56.0rc1 (2022-03-29)
Features
- Allow modules to store already existing 3PID associations. (#12195)
- Allow registering server administrators using the module API. Contributed by Famedly. (#12250)
Bugfixes
- Fix a long-standing bug which caused the
/_matrix/federation/v1/state
and/_matrix/federation/v1/state_ids
endpoints to return incorrect or invalid data when called for an event which we have stored as an "outlier". (#12087) - Fix a long-standing bug where events from ignored users would still be considered for relations. (#12227, #12232, #12285)
- Fix a bug introduced in Synapse 1.53.0 where an unnecessary query could be performed when fetching bundled aggregations for threads. (#12228)
- Fix a bug introduced in Synapse 1.52.0 where admins could not deactivate and GDPR-erase a user if Synapse was configured with limits on avatars. (#12261)
Improved Documentation
- Fix the link to the module documentation in the legacy spam checker warning message. (#12231)
- Remove incorrect prefixes in the worker documentation for some endpoints. (#12243)
- Correct
check_username_for_spam
annotations and docs. (#12246) - Correct Authentik OpenID typo, and add notes on troubleshooting. Contributed by @IronTooch. (#12275)
- HAProxy reverse proxy guide update to stop sending IPv4-mapped address to homeserver. Contributed by @villepeh. (#12279)
Internal Changes
- Rename
shared_rooms
tomutual_rooms
(MSC2666), as per proposal changes. (#12036) - Remove check on
update_user_directory
for shared rooms handler (MSC2666), and update/expand documentation. (#12038) - Refactor
create_new_client_event
to use a new parameter,state_event_ids
, which accurately describes the usage with MSC2716 instead of abusingauth_event_ids
. (#12083, #12304) - Refuse to start if registration is enabled without email, captcha, or token-based verification unless the new config flag
enable_registration_without_verification
is set. (#12091) - Add tests for database transaction callbacks. (#12198)
- Handle cancellation in
DatabasePool.runInteraction
. (#12199) - Add missing type hints for cache storage. (#12216)
- Add missing type hints for storage. (#12248, #12255)
- Add type hints to tests files. (#12224, #12240, #12256)
- Use type stubs for
psycopg2
. (#12269) - Improve type annotations for
execute_values
. (#12311) - Clean-up logic around rebasing URLs for URL image previews. (#12219)
- Use the
ignored_users
table in additional places instead of re-parsing the account data. (#12225) - Refactor the relations endpoints to add a
RelationsHandler
. (#12237) - Generate announcement links in the release script. (#12242)
- Improve error message when dependencies check finds a broken installation. (#12244)
- Compress metrics HTTP resource when enabled. Contributed by Nick @ Beeper. (#12258)
- Refuse to start if the PostgreSQL database has a non-
C
locale, unless the config flagallow_unsafe_db_locale
is set to true. (#12262, #12288) - Optionally include account validity expiration information to experimental MSC3720 account status responses. (#12266)
- Add a new cache
_get_membership_from_event_id
to speed up push rule calculations in large rooms. (#12272) - Re-enable Complement concurrency in CI. (#12283)
- Remove unused test utilities. (#12291)
- Enhance logging for inbound federation events. (#12301)
- Fix compatibility with the recently-released Jinja 3.1. (#12313)
- Avoid trying to calculate the state at outlier events. (#12314)
Synapse 1.55.2 (2022-03-24)
This patch version reverts the earlier fixes from Synapse 1.55.1, which could cause problems in certain deployments, and instead adds a cap to the version of Jinja to be installed. Again, this is to fix an incompatibility with version 3.1.0 of the Jinja library, and again, deployments of Synapse using the matrixdotorg/synapse
Docker image or Debian packages from packages.matrix.org are not affected.
Internal Changes
- Pin Jinja to <3.1.0, as Synapse fails to start with Jinja 3.1.0. (#12297)
- Revert changes from 1.55.1 as they caused problems with older versions of Jinja (#12296)
Synapse 1.55.1 (2022-03-24)
This is a patch release that fixes an incompatibility with version 3.1.0 of the Jinja library, released on March 24th, 2022. Deployments of Synapse using the matrixdotorg/synapse
Docker image or Debian packages from packages.matrix.org are not affected.
Internal Changes
- Remove uses of the long-deprecated
jinja2.Markup
which would prevent Synapse from starting with Jinja 3.1.0 or above installed. (#12289)
Synapse 1.55.0 (2022-03-22)
This release removes a workaround introduced in Synapse 1.50.0 for Mjolnir compatibility. This breaks compatibility with Mjolnir 1.3.1 and earlier. (#11700); Mjolnir users should upgrade Mjolnir before upgrading Synapse to this version.
This release also moves the location of the synctl
script; see the upgrade notes for more details.
Internal Changes
- Tweak copy for default Single Sign-On account details template to better adhere to mobile app store guidelines. (#12265, #12260)
Synapse 1.55.0rc1 (2022-03-15)
Features
- Add third-party rules callbacks
check_can_shutdown_room
andcheck_can_deactivate_user
. (#12028) - Improve performance of logging in for large accounts. (#12132)
- Add experimental env var
SYNAPSE_ASYNC_IO_REACTOR
that causes Synapse to use the asyncio reactor for Twisted. (#12135) - Support the stable identifiers from MSC3440: threads. (#12151)
- Add a new Jinja2 template filter to extract the local part of an email address. (#12212)
Bugfixes
- Use the proper serialization format for bundled thread aggregations. The bug has existed since Synapse v1.48.0. (#12090)
- Fix a long-standing bug when redacting events with relations. (#12113, #12121, #12130, #12189)
- Fix a bug introduced in Synapse 1.7.2 whereby background updates are never run with the default background batch size. (#12157)
- Fix a bug where non-standard information was returned from the
/hierarchy
API. Introduced in Synapse v1.41.0. (#12175) - Fix a bug introduced in Synapse 1.54.0 that broke background updates on sqlite homeservers while search was disabled. (#12215)
- Fix a long-standing bug when a
filter
argument withevent_fields
which did not include theunsigned
field could result in a 500 error on/sync
. (#12234)
Improved Documentation
- Fix complexity checking config example in Resource Constrained Devices docs page. (#11998)
- Improve documentation for demo scripts. (#12143)
- Updates to the Room DAG concepts development document. (#12179)
- Document that the
typing
,to_device
,account_data
,receipts
, andpresence
stream writer can only be used on a single worker. (#12196) - Document that contributors can sign off privately by email. (#12204)
Deprecations and Removals
- Remove workaround introduced in Synapse 1.50.0 for Mjolnir compatibility. Breaks compatibility with Mjolnir 1.3.1 and earlier. (#11700)
- **
synctl
has been moved into intosynapse._scripts
and is exposed as an entry point; see upgrade notes. (#12140) - Remove backwards compatibilty with pagination tokens from the
/relations
and/aggregations
endpoints generated from Synapse < v1.52.0. (#12138) - The groups/communities feature in Synapse has been deprecated. (#12200)
Internal Changes
- Simplify the
ApplicationService
class' set of public methods related to interest checking. (#11915) - Add config settings for background update parameters. (#11980)
- Correct type hints for txredis. (#12042)
- Limit the size of
aggregation_key
on annotations. (#12101) - Add type hints to tests files. (#12108, #12146, #12207, #12208)
- Move scripts to Synapse package and expose as setuptools entry points. (#12118)
- Add support for cancellation to
ReadWriteLock
. (#12120) - Fix data validation to compare to lists, not sequences. (#12128)
- Fix CI not attaching source distributions and wheels to the GitHub releases. (#12131)
- Remove unused mocks from
test_typing
. (#12136) - Give
scripts-dev
scripts suffixes for neater CI config. (#12137) - Move the snapcraft configuration file to
contrib
. (#12142) - Enable MSC3030 Complement tests in CI. (#12144)
- Enable MSC2716 Complement tests in CI. (#12145)
- Add test for
ObservableDeferred
's cancellation behaviour. (#12149) - Use
ParamSpec
in type hints forsynapse.logging.context
. (#12150) - Prune unused jobs from
tox
config. (#12152) - Move CI checks out of tox, to facilitate a move to using poetry. (#12153)
- Avoid generating state groups for local out-of-band leaves. (#12154)
- Avoid trying to calculate the state at outlier events. (#12155, #12173, #12202)
- Fix some type annotations. (#12156)
- Add type hints for
ObservableDeferred
attributes. (#12159) - Use a prebuilt Action for the
tests-done
CI job. (#12161) - Reduce number of DB queries made during processing of
/sync
. (#12163) - Add
delay_cancellation
utility function, which behaves likestop_cancellation
but waits until the originalDeferred
resolves before raising aCancelledError
. (#12180) - Retry HTTP replication failures, this should prevent 502's when restarting stateful workers (main, event persisters, stream writers). Contributed by Nick @ Beeper. (#12182)
- Add cancellation support to
@cached
and@cachedList
decorators. (#12183) - Remove unused variables. (#12187)
- Add combined test for HTTP pusher and push rule. Contributed by Nick @ Beeper. (#12188)
- Rename
HomeServer.get_tcp_replication
toget_replication_command_handler
. (#12192) - Remove some dead code. (#12197)
- Fix a misleading comment in the function
check_event_for_spam
. (#12203) - Remove unnecessary
pass
statements. (#12206) - Update the SSO username picker template to comply with SIWA guidelines. (#12210)
- Improve code documentation for the typing stream over replication. (#12211)
Synapse 1.54.0 (2022-03-08)
Please note that this will be the last release of Synapse that is compatible with Mjolnir 1.3.1 and earlier. Administrators of servers which have the Mjolnir module installed are advised to upgrade Mjolnir to version 1.3.2 or later.
Bugfixes
- Fix a bug introduced in Synapse 1.54.0rc1 preventing the new module callbacks introduced in this release from being registered by modules. (#12141)
- Fix a bug introduced in Synapse 1.54.0rc1 where runtime dependency version checks would mistakenly check development dependencies if they were present and would not accept pre-release versions of dependencies. (#12129, #12177)
Internal Changes
- Update release script to insert the previous version when writing "No significant changes" line in the changelog. (#12127)
- Relax the version guard for "packaging" added in #12088. (#12166)
Synapse 1.54.0rc1 (2022-03-02)
Features
- Add support for MSC3202: sending one-time key counts and fallback key usage states to Application Services. (#11617)
- Improve the generated URL previews for some web pages. Contributed by @AndrewRyanChama. (#11985)
- Track cache invalidations in Prometheus metrics, as already happens for cache eviction based on size or time. (#12000)
- Implement experimental support for MSC3720 (account status endpoints). (#12001, #12067)
- Enable modules to set a custom display name when registering a user. (#12009)
- Advertise Matrix 1.1 and 1.2 support on
/_matrix/client/versions
. (#12020, (#12022) - Support only the stable identifier for MSC3069's
is_guest
on/_matrix/client/v3/account/whoami
. (#12021) - Use room version 9 as the default room version (per MSC3589). (#12058)
- Add module callbacks to react to user deactivation status changes (i.e. deactivations and reactivations) and profile updates. (#12062)
Bugfixes
- Fix a bug introduced in Synapse 1.48.0 where an edit of the latest event in a thread would not be properly applied to the thread summary. (#11992)
- Fix long-standing bug where the
get_rooms_for_user
cache was not correctly invalidated for remote users when the server left a room. (#11999) - Fix a 500 error with Postgres when looking backwards with the MSC3030
/timestamp_to_event?dir=b
endpoint. (#12024) - Properly fix a long-standing bug where wrong data could be inserted into the
event_search
table when using SQLite. This could block runningsynapse_port_db
with anargument of type 'int' is not iterable
error. This bug was partially fixed by a change in Synapse 1.44.0. (#12037) - Fix slow performance of
/logout
in some cases where refresh tokens are in use. The slowness existed since the initial implementation of refresh tokens in version 1.38.0. (#12056) - Fix a long-standing bug where Synapse would make additional failing requests over federation for missing data. (#12077)
- Fix occasional
Unhandled error in Deferred
error message. (#12089) - Fix a bug introduced in Synapse 1.51.0 where incoming federation transactions containing at least one EDU would be dropped if debug logging was enabled for
synapse.8631_debug
. (#12098) - Fix a long-standing bug which could cause push notifications to malfunction if
use_frozen_dicts
was set in the configuration. (#12100) - Fix an extremely rare, long-standing bug in
ReadWriteLock
that would cause an error when a newly unblocked writer completes instantly. (#12105) - Make a
POST
to/rooms/<room_id>/receipt/m.read/<event_id>
only trigger a push notification if the count of unread messages is different to the one in the last successfully sent push. This reduces server load and load on the receiving device. (#11835)
Updates to the Docker image
- The Docker image no longer automatically creates a temporary volume at
/data
. This is not expected to affect normal usage. (#11997) - Use Python 3.9 in Docker images by default. (#12112)
Improved Documentation
- Document support for the
to_device
,account_data
,receipts
, andpresence
stream writers for workers. (#11599) - Explain the meaning of spam checker callbacks' return values. (#12003)
- Clarify information about external Identity Provider IDs. (#12004)
Deprecations and Removals
- Deprecate using
synctl
with the config optionsynctl_cache_factor
and print a warning if a user still uses this option. (#11865) - Remove support for the legacy structured logging configuration (please see the the upgrade notes if you are using
structured: true
in the Synapse configuration). (#12008) - Drop support for MSC3283 unstable flags now that the stable flags are supported. (#12018)
- Remove the unstable
/spaces
endpoint from MSC2946. (#12073)
Internal Changes
- Make the
get_room_version
method useget_room_version_id
to benefit from caching. (#11808) - Remove unnecessary condition on knock -> leave auth rule check. (#11900)
- Add tests for device list changes between local users. (#11972)
- Optimise calculating
device_list
changes in/sync
. (#11974) - Add missing type hints to storage classes. (#11984)
- Refactor the search code for improved readability. (#11991)
- Move common deduplication code down into
_auth_and_persist_outliers
. (#11994) - Limit concurrent joins from applications services. (#11996)
- Preparation for faster-room-join work: when parsing the
send_join
response, get them.room.create
event fromstate
, notauth_chain
. (#12005, #12039) - Preparation for faster-room-join work: parse MSC3706 fields in send_join response. (#12011)
- Preparation for faster-room-join work: persist information on which events and rooms have partial state to the database. (#12012)
- Preparation for faster-room-join work: Support for calling
/federation/v1/state
on a remote server. (#12013) - Configure
tox
to usevenv
rather thanvirtualenv
. (#12015) - Fix bug in
StateFilter.return_expanded()
and add some tests. (#12016) - Use Matrix v1.1 endpoints (
/_matrix/client/v3/auth/...
) in fallback auth HTML forms. (#12019) - Update the
olddeps
CI job to use an old version ofmarkupsafe
. (#12025) - Upgrade Mypy to version 0.931. (#12030)
- Remove legacy
HomeServer.get_datastore()
. (#12031, #12070) - Minor typing fixes. (#12034, #12069)
- After joining a room, create a dedicated logcontext to process the queued events. (#12041)
- Tidy up GitHub Actions config which builds distributions for PyPI. (#12051)
- Move configuration out of
setup.cfg
. (#12052, #12059) - Fix error message when a worker process fails to talk to another worker process. (#12060)
- Fix using the
complement.sh
script without specifying a directory or a branch. Contributed by Nico on behalf of Famedly. (#12063) - Add type hints to
tests/rest/client
. (#12066, #12072, #12084, #12094) - Add some logging to
/sync
to try and track down #11916. (#12068) - Inspect application dependencies using
importlib.metadata
or its backport. (#12088) - Use
assertEqual
instead of the deprecatedassertEquals
in test code. (#12092) - Move experimental support for MSC3440 to
/versions
. (#12099) - Add
stop_cancellation
utility function to stopDeferred
s from being cancelled. (#12106) - Improve exception handling for concurrent execution. (#12109)
- Advertise support for Python 3.10 in packaging files. (#12111)
- Move CI checks out of tox, to facilitate a move to using poetry. (#12119)
Synapse 1.53.0 (2022-02-22)
No significant changes since 1.53.0rc1.
Synapse 1.53.0rc1 (2022-02-15)
Features
- Add experimental support for sending to-device messages to application services, as specified by MSC2409. (#11215, #11966)
- Add a background database update to purge account data for deactivated users. (#11655)
- Experimental support for MSC3666: including bundled aggregations in server side search results. (#11837)
- Enable cache time-based expiry by default. The
expiry_time
config flag has been superseded byexpire_caches
andcache_entry_ttl
. (#11849) - Add a callback to allow modules to allow or forbid a 3PID (email address, phone number) from being associated to a local account. (#11854)
- Stabilize support and remove unstable endpoints for MSC3231. Clients must switch to the stable identifier and endpoint. See the upgrade notes for more information. (#11867)
- Allow modules to retrieve the current instance's server name and worker name. (#11868)
- Use a dedicated configurable rate limiter for 3PID invites. (#11892)
- Support the stable API endpoint for MSC3283: new settings in
/capabilities
endpoint. (#11933, #11989) - Support the
dir
parameter on the/relations
endpoint, per MSC3715. (#11941) - Experimental implementation of MSC3706: extensions to
/send_join
to support reduced response size. (#11967)
Bugfixes
- Fix MSC2716 historical messages backfilling in random order on remote homeservers. (#11114)
- Fix a bug introduced in Synapse 1.51.0 where incoming federation transactions containing at least one EDU would be dropped if debug logging was enabled for
synapse.8631_debug
. (#11890) - Fix a long-standing bug where some unknown endpoints would return HTML error pages instead of JSON
M_UNRECOGNIZED
errors. (#11930) - Implement an allow list of content types for which we will attempt to preview a URL. This prevents Synapse from making useless longer-lived connections to streaming media servers. (#11936)
- Fix a long-standing bug where pagination tokens from
/sync
and/messages
could not be provided to the/relations
API. (#11952) - Require that modules register their callbacks using keyword arguments. (#11975)
- Fix a long-standing bug where
M_WRONG_ROOM_KEYS_VERSION
errors would not include the speccedcurrent_version
field. (#11988)
Improved Documentation
- Fix typo in User Admin API: unpind -> unbind. (#11859)
- Document images returned by the User List Media Admin API can include those generated by URL previews. (#11862)
- Remove outdated MSC1711 FAQ document. (#11907)
- Correct the structured logging configuration example. Contributed by Brad Jones. (#11946)
- Add information on the Synapse release cycle. (#11954)
- Fix broken link in the README to the admin API for password reset. (#11955)
Deprecations and Removals
- Drop support for
webclient
listeners and configuringweb_client_location
to a non-HTTP(S) URL. Deprecated configurations are a configuration error. (#11895) - Remove deprecated
user_may_create_room_with_invites
spam checker callback. See the upgrade notes for more information. (#11950) - No longer build
.deb
packages for Ubuntu 21.04 Hirsute Hippo, which has now EOLed. (#11961)
Internal Changes
- Enhance user registration test helpers to make them more useful for tests involving application services and devices. (#11615, #11616)
- Improve performance when fetching bundled aggregations for multiple events. (#11660, #11752)
- Fix type errors introduced by new annotations in the Prometheus Client library. (#11832)
- Add missing type hints to replication code. (#11856, #11938)
- Ensure that
opentracing
scopes are activated and closed at the right time. (#11869) - Improve opentracing for incoming federation requests. (#11870)
- Improve internal docstrings in
synapse.util.caches
. (#11876) - Do not needlessly clear the
get_users_in_room
andget_users_in_room_with_profiles
caches when any room state changes. (#11878) - Convert
ApplicationServiceTestCase
to usesimple_async_mock
. (#11880) - Remove experimental changes to the default push rules which were introduced in Synapse 1.19.0 but never enabled. (#11884)
- Disable coverage calculation for olddeps build. (#11888)
- Preparation to support sending device list updates to application services. (#11905)
- Add a test that checks users receive their own device list updates down
/sync
. (#11909) - Run Complement tests sequentially. (#11910)
- Various refactors to the application service notifier code. (#11911, #11912)
- Tests: replace mocked
Authenticator
with the real thing. (#11913) - Various refactors to the typing notifications code. (#11914)
- Use the proper type for the
Content-Length
header in theUploadResource
. (#11927) - Remove an unnecessary ignoring of type hints due to fixes in upstream packages. (#11939)
- Add missing type hints. (#11953)
- Fix an import cycle in
synapse.event_auth
. (#11965) - Unpin
frozendict
but exclude the known bad version 2.1.2. (#11969) - Prepare for rename of default Complement branch. (#11971)
- Fetch Synapse's version using a helper from
matrix-common
. (#11979)
Synapse 1.52.0 (2022-02-08)
No significant changes since 1.52.0rc1.
Note that Twisted 22.1.0
has recently been released, which fixes a security issue
within the Twisted library. We do not believe Synapse is affected by this vulnerability,
though we advise server administrators who installed Synapse via pip to upgrade Twisted
with pip install --upgrade Twisted treq
as a matter of good practice. The Docker image
matrixdotorg/synapse
and the Debian packages from packages.matrix.org
are using the
updated library.
Synapse 1.52.0rc1 (2022-02-01)
Features
- Remove account data (including client config, push rules and ignored users) upon user deactivation. (#11621, #11788, #11789)
- Add an admin API to reset connection timeouts for remote server. (#11639)
- Add an admin API to get a list of rooms that federate with a given remote homeserver. (#11658)
- Add a config flag to inhibit
M_USER_IN_USE
during registration. (#11743) - Add a module callback to set username at registration. (#11790)
- Allow configuring a maximum file size as well as a list of allowed content types for avatars. (#11846)
Bugfixes
- Include the bundled aggregations in the
/sync
response, per MSC2675. (#11612) - Fix a long-standing bug when previewing Reddit URLs which do not contain an image. (#11767)
- Fix a long-standing bug that media streams could cause long-lived connections when generating URL previews. (#11784)
- Include a
prev_content
field in state events sent to Application Services. Contributed by @totallynotvaishnav. (#11798) - Fix a bug introduced in Synapse 0.33.3 causing requests to sometimes log strings such as
HTTPStatus.OK
instead of integer status codes. (#11827)
Improved Documentation
- Update pypi installation docs to indicate that we now support Python 3.10. (#11820)
- Add missing steps to the contribution submission process in the documentation. Contributed by @sequentialread. (#11821)
- Remove not needed old table of contents in documentation. (#11860)
- Consolidate the
access_token
information at the top of each relevant page in the Admin API documentation. (#11861)
Deprecations and Removals
- Drop support for Python 3.6, which is EOL. (#11683)
- Remove the
experimental_msc1849_support_enabled
flag as the features are now stable. (#11843)
Internal Changes
- Preparation for database schema simplifications: add
state_key
andrejection_reason
columns toevents
table. (#11792) - Add
FrozenEvent.get_state_key
and use it in a couple of places. (#11793) - Preparation for database schema simplifications: stop reading from
event_reference_hashes
. (#11794) - Drop unused table
public_room_list_stream
. (#11795) - Preparation for reducing Postgres serialization errors: allow setting transaction isolation level. Contributed by Nick @ Beeper. (#11799, #11847)
- Docker: skip the initial amd64-only build and go straight to multiarch. (#11810)
- Run Complement on the Github Actions VM and not inside a Docker container. (#11811)
- Log module names at startup. (#11813)
- Improve type safety of bundled aggregations code. (#11815)
- Correct a type annotation in the event validation logic. (#11817, #11830)
- Minor updates and documentation for database schema delta files. (#11823)
- Workaround a type annotation problem in
prometheus_client
0.13.0. (#11834) - Minor performance improvement in room state lookup. (#11836)
- Fix some indentation inconsistencies in the sample config. (#11838)
- Add type hints to
tests/rest/admin
. (#11851)
Synapse 1.51.0 (2022-01-25)
No significant changes since 1.51.0rc2.
Synapse 1.51.0 deprecates webclient
listeners and non-HTTP(S) web_client_location
s. Support for these will be removed in Synapse 1.53.0, at which point Synapse will not be capable of directly serving a web client for Matrix. See the upgrade notes.
Synapse 1.51.0rc2 (2022-01-24)
Bugfixes
- Fix a bug introduced in Synapse 1.40.0 that caused Synapse to fail to process incoming federation traffic after handling a large amount of events in a v1 room. (#11806)
Synapse 1.50.2 (2022-01-24)
This release includes the same bugfix as Synapse 1.51.0rc2.
Bugfixes
- Fix a bug introduced in Synapse 1.40.0 that caused Synapse to fail to process incoming federation traffic after handling a large amount of events in a v1 room. (#11806)
Synapse 1.51.0rc1 (2022-01-21)
Features
- Add
track_puppeted_user_ips
config flag to record client IP addresses against puppeted users, and include the puppeted users in monthly active user counts. (#11561, #11749, #11757) - Include whether the requesting user has participated in a thread when generating a summary for MSC3440. (#11577)
- Return an
M_FORBIDDEN
error code instead ofM_UNKNOWN
when a spam checker module prevents a user from creating a room. (#11672) - Add a flag to the
synapse_review_recent_signups
script to ignore and filter appservice users. (#11675, #11770)
Bugfixes
- Fix a long-standing issue which could cause Synapse to incorrectly accept data in the unsigned field of events received over federation. (#11530)
- Fix a long-standing bug where Synapse wouldn't cache a response indicating that a remote user has no devices. (#11587)
- Fix an error that occurs whilst trying to get the federation status of a destination server that was working normally. This admin API was newly introduced in Synapse v1.49.0. (#11593)
- Fix bundled aggregations not being included in the
/sync
response, per MSC2675. (#11612, #11659, #11791) - Fix the
/_matrix/client/v1/room/{roomId}/hierarchy
endpoint returning incorrect fields which have been present since Synapse 1.49.0. (#11667) - Fix preview of some GIF URLs (like tenor.com). Contributed by Philippe Daouadi. (#11669)
- Fix a bug where only the first 50 rooms from a space were returned from the
/hierarchy
API. This has existed since the introduction of the API in Synapse v1.41.0. (#11695) - Fix a bug introduced in Synapse v1.18.0 where password reset and address validation emails would not be sent if their subject was configured to use the 'app' template variable. Contributed by @br4nnigan. (#11710, #11745)
- Make the 'List Rooms' Admin API sort stable. Contributed by Daniël Sonck. (#11737)
- Fix a long-standing bug where space hierarchy over federation would only work correctly some of the time. (#11775)
- Fix a bug introduced in Synapse v1.46.0 that prevented
on_logged_out
module callbacks from being correctly awaited by Synapse. (#11786)
Improved Documentation
- Warn against using a Let's Encrypt certificate for TLS/DTLS TURN server client connections, and suggest using ZeroSSL certificate instead. This works around client-side connectivity errors caused by WebRTC libraries that reject Let's Encrypt certificates. Contibuted by @AndrewFerr. (#11686)
- Document the new
SYNAPSE_TEST_PERSIST_SQLITE_DB
environment variable in the contributing guide. (#11715) - Document that the minimum supported PostgreSQL version is now 10. (#11725)
- Fix typo in demo docs: differnt. (#11735)
- Update room spec URL in config files. (#11739)
- Mention
python3-venv
andlibpq-dev
dependencies in the contribution guide. (#11740) - Update documentation for configuring login with Facebook. (#11755)
- Update installation instructions to note that Python 3.6 is no longer supported. (#11781)
Deprecations and Removals
- Remove the unstable
/send_relation
endpoint. (#11682) - Remove
python_twisted_reactor_pending_calls
Prometheus metric. (#11724) - Remove the
password_hash
field from the response dictionaries of the Users Admin API. (#11576) - Deprecate support for
webclient
listeners and non-HTTP(S)web_client_location
configuration. (#11774, #11783)
Internal Changes
- Run
pyupgrade --py37-plus --keep-percent-format
on Synapse. (#11685) - Use buildkit's cache feature to speed up docker builds. (#11691)
- Use
auto_attribs
and native type hints for attrs classes. (#11692, #11768) - Remove debug logging for #4422, which has been closed since Synapse 0.99. (#11693)
- Remove fallback code for Python 2. (#11699)
- Add a test for an edge case in the
/sync
logic. (#11701) - Add the option to write SQLite test dbs to disk when running tests. (#11702)
- Improve Complement test output for Gitub Actions. (#11707)
- Fix docstring on
add_account_data_for_user
. (#11716) - Complement environment variable name change and update
.gitignore
. (#11718) - Simplify calculation of Prometheus metrics for garbage collection. (#11723)
- Improve accuracy of
python_twisted_reactor_tick_time
Prometheus metric. (#11724, #11771) - Minor efficiency improvements when inserting many values into the database. (#11742)
- Invite PR authors to give themselves credit in the changelog. (#11744)
- Add optional debugging to investigate issue 8631. (#11760)
- Remove
log_function
utility function and its uses. (#11761) - Add a unit test that checks both
client
andwebclient
resources will function when simultaneously enabled. (#11765) - Allow overriding complement commit using
COMPLEMENT_REF
. (#11766) - Add some comments and type annotations for
_update_outliers_txn
. (#11776)
Synapse 1.50.1 (2022-01-18)
This release fixes a bug in Synapse 1.50.0 that could prevent clients from being able to connect to Synapse if the webclient
resource was enabled. Further details are available in this issue.
Bugfixes
- Fix a bug introduced in Synapse 1.50.0rc1 that could cause Matrix clients to be unable to connect to Synapse instances with the
webclient
resource enabled. (#11764)
Synapse 1.50.0 (2022-01-18)
This release contains a critical bug that may prevent clients from being able to connect. As such, it is not recommended to upgrade to 1.50.0. Instead, please upgrade straight to to 1.50.1. Further details are available in this issue.
Please note that we now only support Python 3.7+ and PostgreSQL 10+ (if applicable), because Python 3.6 and PostgreSQL 9.6 have reached end-of-life.
No significant changes since 1.50.0rc2.
Synapse 1.50.0rc2 (2022-01-14)
This release candidate fixes a federation-breaking regression introduced in Synapse 1.50.0rc1.
Bugfixes
- Fix a bug introduced in Synapse v1.0.0 whereby some device list updates would not be sent to remote homeservers if there were too many to send at once. (#11729)
- Fix a bug introduced in Synapse v1.50.0rc1 whereby outbound federation could fail because too many EDUs were produced for device updates. (#11730)
Improved Documentation
- Document that now the minimum supported PostgreSQL version is 10. (#11725)
Internal Changes
- Fix a typechecker problem related to our (ab)use of
nacl.signing.SigningKey
s. (#11714)
Synapse 1.50.0rc1 (2022-01-05)
Features
- Allow guests to send state events per MSC3419. (#11378)
- Add experimental support for part of MSC3202: allowing application services to masquerade as specific devices. (#11538)
- Add admin API to get users' account data. (#11664)
- Include the room topic in the stripped state included with invites and knocking. (#11666)
- Send and handle cross-signing messages using the stable prefix. (#10520)
- Support unprefixed versions of fallback key property names. (#11541)
Bugfixes
- Fix a long-standing bug where relations from other rooms could be included in the bundled aggregations of an event. (#11516)
- Fix a long-standing bug which could cause
AssertionError
s to be written to the log when Synapse was restarted after purging events from the database. (#11536, #11642) - Fix a bug introduced in Synapse 1.17.0 where a pusher created for an email with capital letters would fail to be created. (#11547)
- Fix a long-standing bug where responses included bundled aggregations when they should not, per MSC2675. (#11592, #11623)
- Fix a long-standing bug that some unknown endpoints would return HTML error pages instead of JSON
M_UNRECOGNIZED
errors. (#11602) - Fix a bug introduced in Synapse 1.19.3 which could sometimes cause
AssertionError
s when backfilling rooms over federation. (#11632)
Improved Documentation
- Update Synapse install command for FreeBSD as the package is now prefixed with
py38
. Contributed by @itchychips. (#11267) - Document the usage of refresh tokens. (#11427)
- Add details for how to configure a TURN server when behind a NAT. Contibuted by @AndrewFerr. (#11553)
- Add references for using Postgres to the Docker documentation. (#11640)
- Fix the documentation link in newly-generated configuration files. (#11678)
- Correct the documentation for
nginx
to use a case-sensitive url pattern. Fixes an error introduced in v1.21.0. (#11680) - Clarify SSO mapping provider documentation by writing
def
orasync def
before the names of methods, as appropriate. (#11681)
Deprecations and Removals
- Replace
mock
package by its standard library version. (#11588) - Drop support for Python 3.6 and Ubuntu 18.04. (#11633)
Internal Changes
- Allow specific, experimental events to be created without
prev_events
. Used by MSC2716. (#11243) - A test helper (
wait_for_background_updates
) no longer depends on classes defining astore
property. (#11331) - Add type hints to
synapse.appservice
. (#11360) - Add missing type hints to
synapse.config
module. (#11480) - Add test to ensure we share the same
state_group
across the whole historical batch when using the MSC2716/batch_send
endpoint. (#11487) - Refactor
tests.util.setup_test_homeserver
andtests.server.setup_test_homeserver
. (#11503) - Move
glob_to_regex
andre_word_boundary
tomatrix-python-common
. (#11505, #11687) - Use
HTTPStatus
constants in place of literals intests.rest.client.test_auth
. (#11520) - Add a receipt types constant for
m.read
. (#11531) - Clean up
synapse.rest.admin
. (#11535) - Add missing
errcode
toparse_string
andparse_boolean
. (#11542) - Use
HTTPStatus
constants in place of literals insynapse.http
. (#11543) - Add missing type hints to storage classes. (#11546, #11549, #11551, #11555, #11575, #11589, #11594, #11652, #11653, #11654, #11657)
- Fix an inaccurate and misleading comment in the
/sync
code. (#11550) - Add missing type hints to
synapse.logging.context
. (#11556) - Stop populating unused database column
state_events.prev_state
. (#11558) - Minor efficiency improvements in event persistence. (#11560)
- Add some safety checks that storage functions are used correctly. (#11564, #11580)
- Make
get_device
returnNone
if the device doesn't exist rather than raising an exception. (#11565) - Split the HTML parsing code from the URL preview resource code. (#11566)
- Remove redundant
COALESCE()
s aroundCOUNT()
s in database queries. (#11570) - Add missing type hints to
synapse.http
. (#11571) - Add MSC2716 and MSC3030 to
/versions
->unstable_features
to detect server support. (#11582) - Add type hints to
synapse/tests/rest/admin
. (#11590) - Drop end-of-life Python 3.6 and Postgres 9.6 from CI. (#11595)
- Update black version and run it on all the files. (#11596)
- Add opentracing type stubs and fix associated mypy errors. (#11603, #11622)
- Improve OpenTracing support for requests which use a
ResponseCache
. (#11607) - Improve OpenTracing support for incoming HTTP requests. (#11618)
- A number of improvements to opentracing support. (#11619)
- Refactor the way that the
outlier
flag is set on events received over federation. (#11634) - Improve the error messages from
get_create_event_for_room
. (#11638) - Remove redundant
get_current_events_token
method. (#11643) - Convert
namedtuples
toattrs
. (#11665, #11574) - Update the
/capabilities
response to include whether support for MSC3440 is available. (#11690) - Send the
Accept
header in HTTP requests made usingSimpleHttpClient.get_json
. (#11677) - Work around Mjolnir compatibility issue by adding an import for
glob_to_regex
insynapse.util
, where it moved from. (#11696)
Synapse 1.49.2 (2021-12-21)
This release fixes a regression introduced in Synapse 1.49.0 which could cause /sync
requests to take significantly longer. This would particularly affect "initial" syncs for users participating in a large number of rooms, and in extreme cases, could make it impossible for such users to log in on a new client.
Note: in line with our deprecation policy for platform dependencies, this will be the last release to support Python 3.6 and PostgreSQL 9.6, both of which have now reached upstream end-of-life. Synapse will require Python 3.7+ and PostgreSQL 10+.
Note: We will also stop producing packages for Ubuntu 18.04 (Bionic Beaver) after this release, as it uses Python 3.6.
Bugfixes
- Fix a performance regression in
/sync
handling, introduced in 1.49.0. (#11583)
Internal Changes
- Work around a build problem on Debian Buster. (#11625)
Synapse 1.49.1 (2021-12-21)
Not released due to problems building the debian packages.
Synapse 1.49.0 (2021-12-14)
No significant changes since version 1.49.0rc1.
Support for Ubuntu 21.04 ends next month on the 20th of January
For users of Ubuntu 21.04 (Hirsute Hippo), please be aware that upstream support for this version of Ubuntu will end next month. We will stop producing packages for Ubuntu 21.04 after upstream support ends.
The wiki has been migrated to the documentation website
We've decided to move the existing, somewhat stagnant pages from the GitHub wiki to the documentation website.
This was done for two reasons. The first was to ensure that changes are checked by multiple authors before being committed (everyone makes mistakes!) and the second was visibility of the documentation. Not everyone knows that Synapse has some very useful information hidden away in its GitHub wiki pages. Bringing them to the documentation website should help with visibility, as well as keep all Synapse documentation in one, easily-searchable location.
Note that contributions to the documentation website happen through GitHub pull requests. Please visit #synapse-dev:matrix.org if you need help with the process!
Synapse 1.49.0rc1 (2021-12-07)
Features
- Add MSC3030 experimental client and federation API endpoints to get the closest event to a given timestamp. (#9445)
- Include bundled relation aggregations during a limited
/sync
request and/relations
request, per MSC2675. (#11284, #11478) - Add plugin support for controlling database background updates. (#11306, #11475, #11479)
- Support the stable API endpoints for MSC2946: the room
/hierarchy
endpoint. (#11329) - Add admin API to get some information about federation status with remote servers. (#11407)
- Support expiry of refresh tokens and expiry of the overall session when refresh tokens are in use. (#11425)
- Stabilise support for MSC2918 refresh tokens as they have now been merged into the Matrix specification. (#11435, #11522)
- Update MSC2918 refresh token support to confirm with the latest revision: accept the
refresh_tokens
parameter in the request body rather than in the URL parameters. (#11430) - Support configuring the lifetime of non-refreshable access tokens separately to refreshable access tokens. (#11445)
- Expose
synapse_homeserver
andsynapse_worker
commands as entry points to run Synapse's main process and worker processes, respectively. Contributed by @Ma27. (#11449) synctl stop
will now wait for Synapse to exit before returning. (#11459, #11490)- Extend the "delete room" admin api to work correctly on rooms which have previously been partially deleted. (#11523)
- Add support for the
/_matrix/client/v3/login/sso/redirect/{idpId}
API from Matrix v1.1. This endpoint was overlooked when support for v3 endpoints was added in Synapse 1.48.0rc1. (#11451)
Bugfixes
- Fix using MSC2716 batch sending in combination with event persistence workers. Contributed by @tulir at Beeper. (#11220)
- Fix a long-standing bug where all requests that read events from the database could get stuck as a result of losing the database connection, properly this time. Also fix a race condition introduced in the previous insufficient fix in Synapse 1.47.0. (#11376)
- The
/send_join
response now includes the stableevent
field instead of the unstable field from MSC3083. (#11413) - Fix a bug introduced in Synapse 1.47.0 where
send_join
could fail due to an outdatedijson
version. (#11439, #11441, #11460) - Fix a bug introduced in Synapse 1.36.0 which could cause problems fetching event-signing keys from trusted key servers. (#11440)
- Fix a bug introduced in Synapse 1.47.1 where the media repository would fail to work if the media store path contained any symbolic links. (#11446)
- Fix an
LruCache
corruption bug, introduced in Synapse 1.38.0, that would cause certain requests to fail until the next Synapse restart. (#11454) - Fix a long-standing bug where invites from ignored users were included in incremental syncs. (#11511)
- Fix a regression in Synapse 1.48.0 where presence workers would not clear their presence updates over replication on shutdown. (#11518)
- Fix a regression in Synapse 1.48.0 where the module API's
looping_background_call
method would spam errors to the logs when given a non-async function. (#11524)
Updates to the Docker image
- Update
Dockerfile-workers
to healthcheck all workers in the container. (#11429)
Improved Documentation
- Update the media repository documentation. (#11415)
- Update section about backward extremities in the room DAG concepts doc to correct the misconception about backward extremities indicating whether we have fetched an events'
prev_events
. (#11469)
Internal Changes
- Add
Final
annotation to string constants insynapse.api.constants
so that they get typed asLiteral
s. (#11356) - Add a check to ensure that users cannot start the Synapse master process when
worker_app
is set. (#11416) - Add a note about postgres memory management and hugepages to postgres doc. (#11467)
- Add missing type hints to
synapse.config
module. (#11465) - Add missing type hints to
synapse.federation
. (#11483) - Add type annotations to
tests.storage.test_appservice
. (#11488, #11492) - Add type annotations to some of the configuration surrounding refresh tokens. (#11428)
- Add type hints to
synapse/tests/rest/admin
. (#11501) - Add type hints to storage classes. (#11411)
- Add wiki pages to documentation website. (#11402)
- Clean up
tests.storage.test_main
to remove use of legacy code. (#11493) - Clean up
tests.test_visibility
to remove legacy code. (#11495) - Convert status codes to
HTTPStatus
insynapse.rest.admin
. (#11452, #11455) - Extend the
scripts-dev/sign_json
script to support signing events. (#11486) - Improve internal types in push code. (#11409)
- Improve type annotations in
synapse.module_api
. (#11029) - Improve type hints for
LruCache
. (#11453) - Preparation for database schema simplifications: disambiguate queries on
state_key
. (#11497) - Refactor
backfilled
into specific behavior function arguments (_persist_events_and_state_updates
and downstream calls). (#11417) - Refactor
get_version_string
to fix-up types and duplicated code. (#11468) - Refactor various parts of the
/sync
handler. (#11494, #11515) - Remove unnecessary
json.dumps
fromtests.rest.admin
. (#11461) - Save the OpenID Connect session ID on login. (#11482)
- Update and clean up recently ported documentation pages. (#11466)
Synapse 1.48.0 (2021-11-30)
This release removes support for the long-deprecated trust_identity_server_for_password_resets
configuration flag.
This release also fixes some performance issues with some background database updates introduced in Synapse 1.47.0.
No significant changes since 1.48.0rc1.
Synapse 1.48.0rc1 (2021-11-25)
Features
- Experimental support for the thread relation defined in MSC3440. (#11161)
- Support filtering by relation senders & types per MSC3440. (#11236)
- Add support for the
/_matrix/client/v3
and/_matrix/media/v3
APIs from Matrix v1.1. (#11318, #11371) - Support the stable version of MSC2778: the
m.login.application_service
login type. Contributed by @tulir. (#11335) - Add a new version of delete room admin API
DELETE /_synapse/admin/v2/rooms/<room_id>
to run it in the background. Contributed by @dklimpel. (#11223) - Allow the admin Delete Room API to block a room without the need to join it. (#11228)
- Add an admin API to un-shadow-ban a user. (#11347)
- Add an admin API to run background database schema updates. (#11352)
- Add an admin API for blocking a room. (#11324)
- Update the JWT login type to support custom a
sub
claim. (#11361) - Store and allow querying of arbitrary event relations. (#11391)
Bugfixes
- Fix a long-standing bug wherein display names or avatar URLs containing null bytes cause an internal server error when stored in the DB. (#11230)
- Prevent MSC2716 historical state events from being pushed to an application service via
/transactions
. (#11265) - Fix a long-standing bug where uploading extremely thin images (e.g. 1000x1) would fail. Contributed by @Neeeflix. (#11288)
- Fix a bug, introduced in Synapse 1.46.0, which caused the
check_3pid_auth
andon_logged_out
callbacks in legacy password authentication provider modules to not be registered. Modules using the generic module interface were not affected. (#11340) - Fix a bug introduced in 1.41.0 where space hierarchy responses would be incorrectly reused if multiple users were to make the same request at the same time. (#11355)
- Fix a bug introduced in 1.45.0 where the
read_templates
method of the module API would error. (#11377) - Fix an issue introduced in 1.47.0 which prevented servers re-joining rooms they had previously left, if their signing keys were replaced. (#11379)
- Fix a bug introduced in 1.13.0 where creating and publishing a room could cause errors if
room_list_publication_rules
is configured. (#11392) - Improve performance of various background database updates. (#11421, #11422)
Improved Documentation
- Suggest users of the Debian packages add configuration to
/etc/matrix-synapse/conf.d/
to prevent, upon upgrade, being asked to choose between their configuration and the maintainer's. (#11281) - Fix typos in the documentation for the
username_available
admin API. Contributed by Stanislav Motylkov. (#11286) - Add Single Sign-On, SAML and CAS pages to the documentation. (#11298)
- Change the word 'Home server' as one word 'homeserver' in documentation. (#11320)
- Fix missing quotes for wildcard domains in
federation_certificate_verification_whitelist
. (#11381)
Deprecations and Removals
Internal Changes
- Add type annotations to
synapse.metrics
. (#10847) - Split out federated PDU retrieval function into a non-cached version. (#11242)
- Clean up code relating to to-device messages and sending ephemeral events to application services. (#11247)
- Fix a small typo in the error response when a relation type other than 'm.annotation' is passed to
GET /rooms/{room_id}/aggregations/{event_id}
. (#11278) - Drop unused database tables
room_stats_historical
anduser_stats_historical
. (#11280) - Require all files in synapse/ and tests/ to pass mypy unless specifically excluded. (#11282, #11285, #11359)
- Add missing type hints to
synapse.app
. (#11287) - Remove unused parameters on
FederationEventHandler._check_event_auth
. (#11292) - Add type hints to
synapse._scripts
. (#11297) - Fix an issue which prevented the
remove_deleted_devices_from_device_inbox
background database schema update from running when updating from a recent Synapse version. (#11303) - Add type hints to storage classes. (#11307, #11310, #11311, #11312, #11313, #11314, #11316, #11322, #11332, #11339, #11342)
- Add type hints to
synapse.util
. (#11321, #11328) - Improve type annotations in Synapse's test suite. (#11323, #11330)
- Test that room alias deletion works as intended. (#11327)
- Add type annotations for some methods and properties in the module API. (#11341)
- Fix running
scripts-dev/complement.sh
, which was broken in v1.47.0rc1. (#11368) - Rename internal functions for token generation to better reflect what they do. (#11369, #11370)
- Add type hints to configuration classes. (#11377)
- Publish a
develop
image to Docker Hub. (#11380) - Keep fallback key marked as used if it's re-uploaded. (#11382)
- Use
auto_attribs
on theattrs
classRefreshTokenLookupResult
. (#11386) - Rename unstable
access_token_lifetime
configuration option torefreshable_access_token_lifetime
to make it clear it only concerns refreshable access tokens. (#11388) - Do not run the broken MSC2716 tests when running
scripts-dev/complement.sh
. (#11389) - Remove dead code from supporting ACME. (#11393)
- Refactor including the bundled relations when serializing an event. (#11408)
Synapse 1.47.1 (2021-11-23)
This release fixes a security issue in the media store, affecting all prior releases of Synapse. Server administrators are encouraged to update Synapse as soon as possible. We are not aware of these vulnerabilities being exploited in the wild.
Server administrators who are unable to update Synapse may use the workarounds described in the linked GitHub Security Advisory below.
Security advisory
The following issue is fixed in 1.47.1.
-
GHSA-3hfw-x7gx-437c / CVE-2021-41281: Path traversal when downloading remote media.
Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory, potentially outside the media store directory.
The last two directories and file name of the path are chosen randomly by Synapse and cannot be controlled by an attacker, which limits the impact.
Homeservers with the media repository disabled are unaffected. Homeservers configured with a federation whitelist are also unaffected.
Fixed by 91f2bd090.
Synapse 1.47.0 (2021-11-17)
No significant changes since 1.47.0rc3.
Synapse 1.47.0rc3 (2021-11-16)
Bugfixes
- Fix a bug introduced in 1.47.0rc1 which caused worker processes to not halt startup in the presence of outstanding database migrations. (#11346)
- Fix a bug introduced in 1.47.0rc1 which prevented the 'remove deleted devices from
device_inbox
column' background process from running when updating from a recent Synapse version. (#11303, #11353)
Synapse 1.47.0rc2 (2021-11-10)
This fixes an issue with publishing the Debian packages for 1.47.0rc1. It is otherwise identical to 1.47.0rc1.
Synapse 1.47.0rc1 (2021-11-09)
Deprecations and Removals
- The
user_may_create_room_with_invites
module callback is now deprecated. Please refer to the upgrade notes for more information. (#11206) - Remove deprecated admin API to delete rooms (
POST /_synapse/admin/v1/rooms/<room_id>/delete
). (#11213)
Features
- Advertise support for Client-Server API r0.6.1. (#11097)
- Add search by room ID and room alias to the List Room admin API. (#11099)
- Add an
on_new_event
third-party rules callback to allow Synapse modules to act after an event has been sent into a room. (#11126) - Add a module API method to update a user's membership in a room. (#11147)
- Add metrics for thread pool usage. (#11178)
- Support the stable room type field for MSC3288. (#11187)
- Add a module API method to retrieve the current state of a room. (#11204)
- Calculate a default value for
public_baseurl
based onserver_name
. (#11210) - Add support for serving
/.well-known/matrix/server
files, to redirect federation traffic to port 443. (#11211) - Add admin APIs to pause, start and check the status of background updates. (#11263)
Bugfixes
- Fix a long-standing bug which allowed hidden devices to receive to-device messages, resulting in unnecessary database bloat. (#10097)
- Fix a long-standing bug where messages in the
device_inbox
table for deleted devices would persist indefinitely. Contributed by @dklimpel and @JohannesKleine. (#10969, #11212) - Do not accept events if a third-party rule
check_event_allowed
callback raises an exception. (#11033) - Fix long-standing bug where verification requests could fail in certain cases if a federation whitelist was in place but did not include your own homeserver. (#11129)
- Allow an empty list of
state_events_at_start
to be sent when using the MSC2716/batch_send
endpoint and the author of the historical messages is already part of the current room state at the given?prev_event_id
. (#11188) - Fix a bug introduced in Synapse 1.45.0 which prevented the
synapse_review_recent_signups
script from running. Contributed by @samuel-p. (#11191) - Delete
to_device
messages for hidden devices that will never be read, reducing database size. (#11199) - Fix a long-standing bug wherein a missing
Content-Type
header when downloading remote media would cause Synapse to throw an error. (#11200) - Fix a long-standing bug which could result in serialization errors and potentially duplicate transaction data when sending ephemeral events to application services. Contributed by @Fizzadar at Beeper. (#11207)
- Fix a bug introduced in Synapse 1.35.0 which made it impossible to join rooms that return a
send_join
response containing floats. (#11217) - Fix long-standing bug where cross signing keys were not included in the response to
/r0/keys/query
the first time a remote user was queried. (#11234) - Fix a long-standing bug where all requests that read events from the database could get stuck as a result of losing the database connection. (#11240)
- Fix a bug preventing Synapse from being rolled back to an earlier version when using workers. (#11255, #11276)
- Fix a bug introduced in Synapse 1.37.1 which caused a remote event being processed by a worker to not get processed on restart if the worker was killed. (#11262)
- Only allow old Element/Riot Android clients to send read receipts without a request body. All other clients must include a request body as required by the specification. Contributed by @rogersheu. (#11157)
Updates to the Docker image
- Avoid changing user ID when started as a non-root user, and no explicit
UID
is set. (#11209)
Improved Documentation
- Improve example HAProxy config in the docs to properly handle HTTP
Host
headers with port information. This is required for federation over port 443 to work correctly. (#11128) - Add documentation for using Authentik as an OpenID Connect Identity Provider. Contributed by @samip5. (#11151)
- Clarify lack of support for Windows. (#11198)
- Improve code formatting and fix a few typos in docs. Contributed by @sumnerevans at Beeper. (#11221)
- Add documentation for using LemonLDAP as an OpenID Connect Identity Provider. Contributed by @l00ptr. (#11257)
Internal Changes
- Add type annotations for the
log_function
decorator. (#10943) - Add type hints to
synapse.events
. (#11098) - Remove and document unnecessary
RoomStreamToken
checks in application service ephemeral event code. (#11137) - Add type hints so that
synapse.http
passesmypy
checks. (#11164) - Update scripts to pass Shellcheck lints. (#11166)
- Add knock information in admin export. Contributed by Rafael Gonçalves. (#11171)
- Add tests to check that
ClientIpStore.get_last_client_ip_by_device
andget_user_ip_and_agents
combine database and in-memory data correctly. (#11179) - Refactor
Filter
to check different fields depending on the data type. (#11194) - Improve type hints for the relations datastore. (#11205)
- Replace outdated links in the pull request checklist with links to the rendered documentation. (#11225)
- Fix a bug in unit test
test_block_room_and_not_purge
. (#11226) - In
ObservableDeferred
, run observers in the order they were registered. (#11229) - Minor speed up to start up times and getting updates for groups by adding missing index to
local_group_updates.stream_id
. (#11231) - Add
twine
andtowncrier
as dev dependencies, as they're used by the release script. (#11233) - Allow
stream_writers.typing
config to be a list of one worker. (#11237) - Remove debugging statement in tests. (#11239)
- Fix MSC2716 historical messages backfilling in random order on remote homeservers. (#11244)
- Add an additional test for the
cachedList
method decorator. (#11246) - Make minor correction to the type of
auth_checkers
callbacks. (#11253) - Clean up trivial aspects of the Debian package build tooling. (#11269, #11273)
- Blacklist new SyTest that checks that key uploads are valid pending the validation being implemented in Synapse. (#11270)
Synapse 1.46.0 (2021-11-02)
The cause of the performance regression affecting Synapse 1.44 has been identified and fixed. (#11177)
Bugfixes
- Fix a bug introduced in v1.46.0rc1 where URL previews of some XML documents would fail. (#11196)
Synapse 1.46.0rc1 (2021-10-27)
Features
- Add support for Ubuntu 21.10 "Impish Indri". (#11024)
- Port the Password Auth Providers module interface to the new generic interface. (#10548, #11180)
- Experimental support for the thread relation defined in MSC3440. (#11088, #11181, #11192)
- Users admin API can now also modify user type in addition to allowing it to be set on user creation. (#11174)
Bugfixes
- Newly-created public rooms are now only assigned an alias if the room's creation has not been blocked by permission settings. Contributed by @AndrewFerr. (#10930)
- Fix a long-standing bug which meant that events received over federation were sometimes incorrectly accepted into the room state. (#11001, #11009, #11012)
- Fix 500 error on
/messages
when the server accumulates more than 5 backwards extremities at a given depth for a room. (#11027) - Fix a bug where setting a user's
external_id
via the admin API returns 500 and deletes user's existing external mappings if that external ID is already mapped. (#11051) - Fix a long-standing bug where users excluded from the user directory were added into the directory if they belonged to a room which became public or private. (#11075)
- Fix a long-standing bug when attempting to preview URLs which are in the
windows-1252
character encoding. (#11077, #11089) - Fix broken export-data admin command and add test script checking the command to CI. (#11078)
- Show an error when timestamp in seconds is provided to the
/purge_media_cache
Admin API. (#11101) - Fix local users who left all their rooms being removed from the user directory, even if the
search_all_users
config option was enabled. (#11103) - Fix a bug which caused the module API's
get_user_ip_and_agents
function to always fail on workers.get_user_ip_and_agents
was introduced in 1.44.0 and did not function correctly on worker processes at the time. (#11112) - Identity server connection is no longer ignoring
ip_range_whitelist
. (#11120) - Fix a bug introduced in Synapse 1.45.0 breaking the configuration file parsing script. (#11145)
- Fix a performance regression introduced in 1.44.0 which could cause client requests to time out when making large numbers of outbound requests. (#11177, #11190)
- Resolve and share
state_groups
for all MSC2716 historical events in batch. (#10975)
Improved Documentation
- Fix broken links relating to module API deprecation in the upgrade notes. (#11069)
- Add more information about what happens when a user is deactivated. (#11083)
- Clarify the the sample log config can be copied from the documentation without issue. (#11092)
- Update the admin API documentation with an updated list of the characters allowed in registration tokens. (#11093)
- Document Synapse's behaviour when dealing with multiple modules registering the same callbacks and/or handlers for the same HTTP endpoints. (#11096)
- Fix instances of
[example]{.title-ref}
in the upgrade documentation as a result of prior RST to Markdown conversion. (#11118) - Document the version of Synapse each module callback was introduced in. (#11132)
- Document the version of Synapse that introduced each module API method. (#11183)
Internal Changes
- Fix spurious warnings about losing the logging context on the
ReplicationCommandHandler
when losing the replication connection. (#10984) - Include rejected status when we log events. (#11008)
- Add some extra logging to the event persistence code. (#11014)
- Rearrange the internal workings of the incremental user directory updates. (#11035)
- Fix a long-standing bug where users excluded from the directory could still be added to the
users_who_share_private_rooms
table after a regular user joins a private room. (#11143) - Add and improve type hints. (#10972, #11055, #11066, #11076, #11095, #11109, #11121, #11146)
- Mark the Synapse package as containing type annotations and fix export declarations so that Synapse pluggable modules may be type checked against Synapse. (#11054)
- Remove dead code from
MediaFilePaths
. (#11056) - Be more lenient when parsing oEmbed response versions. (#11065)
- Create a separate module for the retention configuration. (#11070)
- Clean up some of the federation event authentication code for clarity. (#11115, #11116, #11122)
- Add docstrings and comments to the application service ephemeral event sending code. (#11138)
- Update the
sign_json
script to support inline configuration of the signing key. (#11139) - Fix broken link in the docker image README. (#11144)
- Always dump logs from unit tests during CI runs. (#11068)
- Add tests for
MediaFilePaths
class. (#11057) - Simplify the user admin API tests. (#11048)
- Add a test for the workaround introduced in #11042 concerning the behaviour of third-party rule modules and
SynapseError
s. (#11071)
Synapse 1.45.1 (2021-10-20)
Bugfixes
- Revert change to counting of deactivated users towards the monthly active users limit, introduced in 1.45.0rc1. (#11127)
Synapse 1.45.0 (2021-10-19)
No functional changes since Synapse 1.45.0rc2.
Known Issues
-
A suspected performance regression which was first reported after the release of 1.44.0 remains unresolved.
We have not been able to identify a probable cause. Affected users report that setting up a federation sender worker appears to alleviate symptoms of the regression.
Improved Documentation
- Reword changelog to clarify concerns about a suspected performance regression in 1.44.0. (#11117)
Synapse 1.45.0rc2 (2021-10-14)
This release candidate fixes a user directory bug present in 1.45.0rc1.
Known Issues
-
A suspected performance regression which was first reported after the release of 1.44.0 remains unresolved.
We have not been able to identify a probable cause. Affected users report that setting up a federation sender worker appears to alleviate symptoms of the regression.
Bugfixes
- Fix a long-standing bug when using multiple event persister workers where events were not correctly sent down
/sync
due to a race. (#11045) - Fix a bug introduced in Synapse 1.45.0rc1 where the user directory would stop updating if it processed an event from a
user not in the
users
table. (#11053) - Fix a bug introduced in Synapse 1.44.0 when logging errors during oEmbed processing. (#11061)
Internal Changes
- Add an 'approximate difference' method to
StateFilter
. (#10825) - Fix inconsistent behavior of
get_last_client_by_ip
when reporting data that has not been stored in the database yet. (#10970) - Fix a bug introduced in Synapse 1.21.0 that causes opentracing and Prometheus metrics for replication requests to be measured incorrectly. (#10996)
- Ensure that cache config tests do not share state. (#11036)
Synapse 1.45.0rc1 (2021-10-12)
Note: Media storage providers module that read from Synapse's configuration need changes as of this version, see the upgrade notes for more information.
Known Issues
- We are investigating a performance issue which was reported after the release of 1.44.0.
- We are aware of a bug with the user directory when using application services. A second release candidate is expected which will resolve this.
Features
- Add MSC3069 support to
/account/whoami
. (#9655) - Support autodiscovery of oEmbed previews. (#10822)
- Add a
user_may_send_3pid_invite
spam checker callback for modules to allow or deny 3PID invites. (#10894) - Add a spam checker callback to allow or deny room joins. (#10910)
- Include an
update_synapse_database
script in the distribution. Contributed by @Fizzadar at Beeper. (#10954) - Include exception information in JSON logging output. Contributed by @Fizzadar at Beeper. (#11028)
Bugfixes
- Fix a minor bug in the response to
/_matrix/client/r0/voip/turnServer
. Contributed by @lukaslihotzki. (#10922) - Fix a bug where empty
yyyy-mm-dd/
directories would be left behind in the media store'surl_cache_thumbnails/
directory. (#10924) - Fix a bug introduced in Synapse v1.40.0 where the signature checks for room version 8 and 9 could be applied to earlier room versions in some situations. (#10927)
- Fix a long-standing bug wherein deactivated users still count towards the monthly active users limit. (#10947)
- Fix a long-standing bug which meant that events received over federation were sometimes incorrectly accepted into the room state. (#10956)
- Fix a long-standing bug where rebuilding the user directory wouldn't exclude support and deactivated users. (#10960)
- Fix MSC2716
/batch_send
endpoint rejecting subsequent batches with unknown batch ID error in existing room versions from the room creator. (#10962) - Fix a bug that could leak local users' per-room nicknames and avatars when the user directory is rebuilt. (#10981)
- Fix a long-standing bug where the remainder of a batch of user directory changes would be silently dropped if the server left a room early in the batch. (#10982)
- Correct a bugfix introduced in Synapse v1.44.0 that would catch the wrong error if a connection is lost before a response could be written to it. (#10995)
- Fix a long-standing bug where local users' per-room nicknames/avatars were visible to anyone who could see you in the user directory. (#11002)
- Fix a long-standing bug where a user's per-room nickname/avatar would overwrite their profile in the user directory when a room was made public. (#11003)
- Work around a regression, introduced in Synapse v1.39.0, that caused
SynapseError
s raised by the experimental third-party rules module callbackcheck_event_allowed
to be ignored. (#11042) - Fix a bug in MSC2716 insertion events in rooms that could cause cross-talk/conflicts between batches. (#10877)
Improved Documentation
- Change wording ("reference homeserver") in Synapse repository documentation. Contributed by @maxkratz. (#10971)
- Fix a dead URL in development documentation (SAML) and change wording from "Riot" to "Element". Contributed by @maxkratz. (#10973)
- Add additional content to the Welcome and Overview page of the documentation. (#10990)
- Update links to MSCs in documentation. Contributed by @dklimpel. (#10991)
Internal Changes
- Improve type hinting in
synapse.util
. (#10888) - Add further type hints to
synapse.storage.util
. (#10892) - Fix type hints to be compatible with an upcoming change to Twisted. (#10895)
- Update utility code to handle C implementations of frozendict. (#10902)
- Drop old functionality which maintained database compatibility with Synapse versions before v1.31. (#10903)
- Clean-up configuration helper classes for the
ServerConfig
class. (#10915) - Use direct references to config flags. (#10916, #10959, #10985)
- Clean up some of the federation event authentication code for clarity. (#10926, #10940, #10986, #10987, #10988, #11010, #11011)
- Refactor various parts of the codebase to use
RoomVersion
objects instead of room version identifier strings. (#10934) - Refactor user directory tests in preparation for upcoming changes. (#10935)
- Include the event id in the logcontext when handling PDUs received over federation. (#10936)
- Fix logged errors in unit tests. (#10939)
- Fix a broken test to ensure that consent configuration works during registration. (#10945)
- Add type hints to filtering classes. (#10958)
- Add type-hint to
HomeserverTestcase.setup_test_homeserver
. (#10961) - Fix the test utility function
create_room_as
so thatis_public=True
will explicitly set thevisibility
parameter of room creation requests topublic
. Contributed by @AndrewFerr. (#10963) - Make the release script more robust and transparent. (#10966)
- Refactor MSC2716
/batch_send
mega function into smaller handler functions. (#10974) - Log stack traces when a missing opentracing span is detected. (#10983)
- Update GHA config to run tests against Python 3.10 and PostgreSQL 14. (#10992)
- Fix a long-standing bug where
ReadWriteLock
s could drop logging contexts on exit. (#10993) - Add a
CODEOWNERS
file to automatically request reviews from the@matrix-org/synapse-core
team on new pull requests. (#10994) - Add further type hints to
synapse.state
. (#11004) - Remove the deprecated
BaseHandler
object. (#11005) - Bump mypy version for CI to 0.910, and pull in new type stubs for dependencies. (#11006)
- Fix CI to run the unit tests without optional deps. (#11017)
- Ensure that cache config tests do not share state. (#11019)
- Add additional type hints to
synapse.server_notices
. (#11021) - Add additional type hints for
synapse.push
. (#11023) - When installing the optional developer dependencies, also include the dependencies needed for type-checking and unit testing. (#11034)
- Remove unnecessary list comprehension from
synapse_port_db
to satisfy code style requirements. (#11043)
Synapse 1.44.0 (2021-10-05)
No significant changes since 1.44.0rc3.
Synapse 1.44.0rc3 (2021-10-04)
Bugfixes
- Fix a bug introduced in Synapse v1.40.0 where changing a user's display name or avatar in a restricted room would cause an authentication error. (#10933)
- Fix
/admin/whois/{user_id}
endpoint, which was broken in v1.44.0rc1. (#10968)
Synapse 1.44.0rc2 (2021-09-30)
Bugfixes
- Fix a bug introduced in v1.44.0rc1 which caused the experimental MSC2716
/batch_send
endpoint to return a 500 error. (#10938) - Fix a bug introduced in v1.44.0rc1 which prevented sending presence events to application services. (#10944)
Improved Documentation
- Minor updates to the installation instructions. (#10919)
Synapse 1.44.0rc1 (2021-09-29)
Features
- Only allow the MSC2716
/batch_send?chunk_id=xxx
endpoint to connect to an already existing insertion event. (#10776) - Improve oEmbed URL previews by processing the author name, photo, and video information. (#10814, #10819)
- Speed up responding with large JSON objects to requests. (#10868, #10905)
- Add a
user_may_create_room_with_invites
spam checker callback to allow modules to allow or deny a room creation request based on the invites and/or 3PID invites it includes. (#10898)
Bugfixes
- Fix a long-standing bug that caused an
AssertionError
when purging history in certain rooms. Contributed by @Kokokokoka. (#10690) - Fix a long-standing bug which caused deactivated users that were later reactivated to be missing from the user directory. (#10782)
- Fix a long-standing bug that caused unbanning a user by sending a membership event to fail. Contributed by @aaronraimist. (#10807)
- Fix a long-standing bug where logging contexts would go missing when federation requests time out. (#10810)
- Fix a long-standing bug causing an error in the deprecated
/initialSync
endpoint when using the undocumentedfrom
andto
parameters. (#10827) - Fix a bug causing the
remove_stale_pushers
background job to repeatedly fail and log errors. This bug affected Synapse servers that had been upgraded from version 1.28 or older and are using SQLite. (#10843) - Fix a long-standing bug in Unicode support of the room search admin API breaking search for rooms with non-ASCII characters. (#10859)
- Fix a bug introduced in Synapse 1.37.0 which caused
knock
membership events which we sent to remote servers to be incorrectly stored in the local database. (#10873) - Fix invalidating one-time key count cache after claiming keys. The bug was introduced in Synapse v1.41.0. Contributed by Tulir at Beeper. (#10875)
- Fix a long-standing bug causing application service users to be subject to MAU blocking if the MAU limit had been reached, even if configured not to be blocked. (#10881)
- Fix a long-standing bug which could cause events pulled over federation to be incorrectly rejected. (#10907)
- Fix a long-standing bug causing URL cache files to be stored in storage providers. Server admins may safely delete the
url_cache/
andurl_cache_thumbnails/
directories from any configured storage providers to reclaim space. (#10911) - Fix a long-standing bug leading to race conditions when creating media store and config directories. (#10913)
Improved Documentation
- Fix some crashes in the Module API example code, by adding JSON encoding/decoding. (#10845)
- Add developer documentation about experimental configuration flags. (#10865)
- Properly remove deleted files from GitHub pages when generating the documentation. (#10869)
Internal Changes
- Fix GitHub Actions config so we can run sytest on synapse from parallel branches. (#10659)
- Split out MSC2716 meta events to their own fields in the
/batch_send
response. (#10777) - Add missing type hints to REST servlets. (#10785, #10817)
- Simplify the internal logic which maintains the user directory database tables. (#10796)
- Use direct references to config flags. (#10812, #10885, #10893, #10897)
- Specify the type of token in generic "Invalid token" error messages. (#10815)
- Make
StateFilter
frozen so it is hashable. (#10816) - Fix a long-standing bug where an
m.room.message
event containing a null byte would cause an internal server error. (#10820) - Add type hints to the state database. (#10823)
- Opt out of cache expiry for
get_users_who_share_room_with_user
, to hopefully improve/sync
performance when you haven't synced recently. (#10826) - Track cache eviction rates more finely in Prometheus's monitoring. (#10829)
- Add missing type hints to
synapse.handlers
. (#10831, #10856) - Extend the Module API to let plug-ins check whether an ID is local and to access IP + User Agent data. (#10833)
- Factor out PNG image data to a constant to be used in several tests. (#10834)
- Add a test to ensure state events sent by modules get persisted correctly. (#10835)
- Rename MSC2716 fields and event types from
chunk
tobatch
to match the/batch_send
endpoint. (#10838) - Rename MSC2716
/batch_send
query parameter from?prev_event
to more obvious usage with?prev_event_id
. (#10839) - Add type hints to
synapse.http.site
. (#10867) - Include outlier status when we log V2 or V3 events. (#10879)
- Break down Grafana's cache expiry time series based on reason for eviction, c.f. #10829. (#10880)
- Clean up some of the federation event authentication code for clarity. (#10883, #10884, #10896, #10901)
- Allow the
.
and~
characters when creating registration tokens as per the change to MSC3231. (#10887) - Clean up some unnecessary parentheses in places around the codebase. (#10889)
- Improve type hinting in the user directory code. (#10891)
- Update development testing script
test_postgresql.sh
to use a supported Python version and make re-runs quicker. (#10906) - Document and summarize changes in schema version
61
–64
. (#10917) - Update release script to sign the newly created git tags. (#10925)
- Fix Debian builds due to
dh-virtualenv
no longer being able to build their docs. (#10931)
Synapse 1.43.0 (2021-09-21)
This release drops support for the deprecated, unstable API for MSC2858 (Multiple SSO Identity Providers), as well as the undocumented experimental.msc2858_enabled
config option. Client authors should update their clients to use the stable API, available since Synapse 1.30.
The documentation has been updated with configuration for routing /spaces
, /hierarchy
and /summary
to workers. See the upgrade notes for more details.
No significant changes since 1.43.0rc2.
Synapse 1.43.0rc2 (2021-09-17)
Bugfixes
Synapse 1.43.0rc1 (2021-09-14)
Features
- Allow room creators to send historical events specified by MSC2716 in existing room versions. (#10566)
- Add config option to use non-default manhole password and keys. (#10643)
- Skip final GC at shutdown to improve restart performance. (#10712)
- Allow configuration of the oEmbed URLs used for URL previews. (#10714, #10759)
- Prefer room version 9 for restricted rooms per the room version capabilities API. (#10772)
Bugfixes
- Fix a long-standing bug where room avatars were not included in email notifications. (#10658)
- Fix a bug where the ordering algorithm was skipping the
origin_server_ts
step in the spaces summary resulting in unstable room orderings. (#10730) - Fix edge case when persisting events into a room where there are multiple events we previously hadn't calculated auth chains for (and hadn't marked as needing to be calculated). (#10743)
- Fix a bug which prevented calls to
/createRoom
that included theroom_alias_name
parameter from being handled by worker processes. (#10757) - Fix a bug which prevented user registration via SSO to require consent tracking for SSO mapping providers that don't prompt for Matrix ID selection. Contributed by @AndrewFerr. (#10733)
- Only return the stripped state events for the
m.space.child
events in a room for the spaces summary from MSC2946. (#10760) - Properly handle room upgrades of spaces. (#10774)
- Fix a bug which generated invalid homeserver config when the
frontend_proxy
worker type was passed to the Synapse Worker-based Complement image. (#10783)
Improved Documentation
- Minor fix to the
media_repository
developer documentation. Contributed by @cuttingedge1109. (#10556) - Update the documentation to note that the
/spaces
and/hierarchy
endpoints can be routed to workers. (#10648) - Clarify admin API documentation on undoing room deletions. (#10735)
- Split up the modules documentation and add examples for module developers. (#10758)
- Correct 2 typographical errors in the Log Contexts documentation. (#10795)
- Fix a wording mistake in the sample configuration. Contributed by @bramvdnheuvel:nltrix.net. (#10804)
Deprecations and Removals
- Remove the unstable MSC2858 API, including the undocumented
experimental.msc2858_enabled
config option. The unstable API has been deprecated since Synapse 1.35. Client authors should update their clients to use the stable API introduced in Synapse 1.30 if they have not already done so. (#10693)
Internal Changes
- Add OpenTracing logging to help debug stuck messages (as described by issue #9424). (#10704)
- Add type annotations to the
synapse.util
package. (#10601) - Ensure
rooms.creator
field is always populated for easy lookup in MSC2716 usage later. (#10697) - Add missing type hints to REST servlets. (#10707, #10728, #10736)
- Do not include rooms with unknown room versions in the spaces summary results. (#10727)
- Additional error checking for the
preset
field when creating a room. (#10738) - Clean up some of the federation event authentication code for clarity. (#10744, #10745, #10746, #10771, #10773, #10781)
- Add an index to
presence_stream
to hopefully speed up startups a little. (#10748) - Refactor event size checking code to simplify searching the codebase for the origins of certain error strings that are occasionally emitted. (#10750)
- Move tests relating to rooms having encryption out of the user directory tests. (#10752)
- Use
attrs
internally for the URL preview code & update documentation. (#10753) - Minor speed ups when joining large rooms over federation. (#10754, #10755, #10756, #10780, #10784)
- Add a constant for
m.federate
. (#10775) - Add a script to update the Debian changelog in a Docker container for systems that are not Debian-based. (#10778)
- Change the format of authenticated users in logs when a user is being puppeted by and admin user. (#10779)
- Remove fixed and flakey tests from the Sytest blacklist. (#10788)
- Improve internal details of the user directory code. (#10789)
- Use direct references to config flags. (#10798)
- Ensure the Rust reporter passes type checking with jaeger-client 4.7's type annotations. (#10799)
Synapse 1.42.0 (2021-09-07)
This version of Synapse removes deprecated room-management admin APIs, removes out-of-date email pushers, and improves error handling for fallback templates for user-interactive authentication. For more information on these points, server administrators are encouraged to read the upgrade notes.
No significant changes since 1.42.0rc2.
Synapse 1.42.0rc2 (2021-09-06)
Features
Internal Changes
- Print a warning when using one of the deprecated
template_dir
settings. (#10768)
Synapse 1.42.0rc1 (2021-09-01)
Features
- Add support for MSC3231: Token authenticated registration. Users can be required to submit a token during registration to authenticate themselves. Contributed by Callum Brown. (#10142)
- Add support for MSC3283: Expose
enable_set_displayname
in capabilities. (#10452) - Port the
PresenceRouter
module interface to the new generic interface. (#10524) - Add pagination to the spaces summary based on updates to MSC2946. (#10613, #10725)
Bugfixes
- Validate new
m.room.power_levels
events. Contributed by @aaronraimist. (#10232) - Display an error on User-Interactive Authentication fallback pages when authentication fails. Contributed by Callum Brown. (#10561)
- Remove pushers when deleting an e-mail address from an account. Pushers for old unlinked emails will also be deleted. (#10581, #10734)
- Reject Client-Server
/keys/query
requests which providedevice_ids
incorrectly. (#10593) - Rooms with unsupported room versions are no longer returned via
/sync
. (#10644) - Enforce the maximum length for per-room display names and avatar URLs. (#10654)
- Fix a bug which caused the
synapse_user_logins_total
Prometheus metric not to be correctly initialised on restart. (#10677) - Improve
ServerNoticeServlet
to avoid duplicate requests and add unit tests. (#10679) - Fix long-standing issue which caused an error when a thumbnail is requested and there are multiple thumbnails with the same quality rating. (#10684)
- Fix a regression introduced in v1.41.0 which affected the performance of concurrent fetches of large sets of events, in extreme cases causing the process to hang. (#10703)
- Fix a regression introduced in Synapse 1.41 which broke email transmission on Systems using older versions of the Twisted library. (#10713)
Improved Documentation
- Add documentation on how to connect Django with Synapse using OpenID Connect and django-oauth-toolkit. Contributed by @HugoDelval. (#10192)
- Advertise https://matrix-org.github.io/synapse documentation in the
README
andCONTRIBUTING
files. (#10595) - Fix some of the titles not rendering in the OpenID Connect documentation. (#10639)
- Minor clarifications to the documentation for reverse proxies. (#10708)
- Remove table of contents from the top of installation and contributing documentation pages. (#10711)
Deprecations and Removals
- Remove deprecated Shutdown Room and Purge Room Admin API. (#8830)
Internal Changes
- Improve type hints for the proxy agent and SRV resolver modules. Contributed by @dklimpel. (#10608)
- Clean up some of the federation event authentication code for clarity. (#10614, #10615, #10624, #10640)
- Add a comment asking developers to leave a reason when bumping the database schema version. (#10621)
- Remove not needed database updates in modify user admin API. (#10627)
- Convert room member storage tuples to
attrs
classes. (#10629, #10642) - Use auto-attribs for the attrs classes used in sync. (#10630)
- Make
backfill
andget_missing_events
use the same codepath. (#10645) - Improve the performance of the
/hierarchy
API (from MSC2946) by caching responses received over federation. (#10647) - Run a nightly CI build against Twisted trunk. (#10651, #10672)
- Do not print out stack traces for network errors when fetching data over federation. (#10662)
- Simplify tests for device admin rest API. (#10664)
- Add missing type hints to REST servlets. (#10665, #10666, #10674)
- Flatten the
tests.synapse.rests
package by moving the contents ofv1
andv2_alpha
into the parent. (#10667) - Update
complement.sh
to rebuild the base Docker image when run with workers. (#10686) - Split the event-processing methods in
FederationHandler
into a separateFederationEventHandler
. (#10692) - Remove unused
compare_digest
function. (#10706)
Synapse 1.41.1 (2021-08-31)
Due to the two security issues highlighted below, server administrators are encouraged to update Synapse. We are not aware of these vulnerabilities being exploited in the wild.
Security advisory
The following issues are fixed in v1.41.1.
-
GHSA-3x4c-pq33-4w3q / CVE-2021-39164: Enumerating a private room's list of members and their display names.
If an unauthorized user both knows the Room ID of a private room and that room's history visibility is set to
shared
, then they may be able to enumerate the room's members, including their display names.The unauthorized user must be on the same homeserver as a user who is a member of the target room.
Fixed by 52c7a51cf.
-
GHSA-jj53-8fmw-f2w2 / CVE-2021-39163: Disclosing a private room's name, avatar, topic, and number of members.
If an unauthorized user knows the Room ID of a private room, then its name, avatar, topic, and number of members may be disclosed through Group / Community features.
The unauthorized user must be on the same homeserver as a user who is a member of the target room, and their homeserver must allow non-administrators to create groups (
enable_group_creation
in the Synapse configuration; off by default).Fixed by cb35df940a, #10723.
Bugfixes
- Fix a regression introduced in Synapse 1.41 which broke email transmission on systems using older versions of the Twisted library. (#10713)
Synapse 1.41.0 (2021-08-24)
This release adds support for Debian 12 (Bookworm), but removes support for Ubuntu 20.10 (Groovy Gorilla), which reached End of Life last month.
Note that when using workers the /_synapse/admin/v1/users/{userId}/media
must now be handled by media workers. See the upgrade notes for more information.
Features
- Enable room capabilities (MSC3244) by default and set room version 8 as the preferred room version when creating restricted rooms. (#10571)
Synapse 1.41.0rc1 (2021-08-18)
Features
- Add
get_userinfo_by_id
method to ModuleApi. (#9581) - Initial local support for MSC3266, Room Summary over the unstable
/rooms/{roomIdOrAlias}/summary
API. (#10394) - Experimental support for MSC3288, sending
room_type
to the identity server for 3pid invites over the/store-invite
API. (#10435) - Add support for sending federation requests through a proxy. Contributed by @Bubu and @dklimpel. See the upgrade notes for more information. (#10596). (#10475)
- Add support for "marker" events which makes historical events discoverable for servers that already have all of the scrollback history (part of MSC2716). (#10498)
- Add a configuration setting for the time a
/sync
response is cached for. (#10513) - The default logging handler for new installations is now
PeriodicallyFlushingMemoryHandler
, a buffered logging handler which periodically flushes itself. (#10518) - Add support for new redaction rules for historical events specified in MSC2716. (#10538)
- Add a setting to disable TLS when sending email. (#10546)
- Add pagination to the spaces summary based on updates to MSC2946. (#10549, #10560, #10569, #10574, #10575, #10579, #10583)
- Admin API to delete several media for a specific user. Contributed by @dklimpel. (#10558, #10628)
- Add support for routing
/createRoom
to workers. (#10564) - Update the Synapse Grafana dashboard. (#10570)
- Add an admin API (
GET /_synapse/admin/username_available
) to check if a username is available (regardless of registration settings). (#10578) - Allow editing a user's
external_ids
via the "Edit User" admin API. Contributed by @dklimpel. (#10598) - The Synapse manhole no longer needs coroutines to be wrapped in
defer.ensureDeferred
. (#10602) - Add option to allow modules to run periodic tasks on all instances, rather than just the one configured to run background tasks. (#10638)
Bugfixes
- Add some clarification to the sample config file. Contributed by @Kentokamoto. (#10129)
- Fix a long-standing bug where protocols which are not implemented by any appservices were incorrectly returned via
GET /_matrix/client/r0/thirdparty/protocols
. (#10532) - Fix exceptions in logs when failing to get remote room list. (#10541)
- Fix longstanding bug which caused the user's presence "status message" to be reset when the user went offline. Contributed by @dklimpel. (#10550)
- Allow public rooms to be previewed in the spaces summary APIs from MSC2946. (#10580)
- Fix a bug introduced in v1.37.1 where an error could occur in the asynchronous processing of PDUs when the queue was empty. (#10592)
- Fix errors on /sync when read receipt data is a string. Only affects homeservers with the experimental flag for MSC2285 enabled. Contributed by @SimonBrandner. (#10606)
- Additional validation for the spaces summary API to avoid errors like
ValueError: Stop argument for islice() must be None or an integer
. The missing validation has existed since v1.31.0. (#10611) - Revert behaviour introduced in v1.38.0 that strips
org.matrix.msc2732.device_unused_fallback_key_types
from/sync
when its value is empty. This field should instead always be present according to MSC2732. (#10623)
Improved Documentation
- Add documentation for configuring a forward proxy. (#10443)
- Updated the reverse proxy documentation to highlight the homserver configuration that is needed to make Synapse aware that is is intentionally reverse proxied. (#10551)
- Update CONTRIBUTING.md to fix index links and the instructions for SyTest in docker. (#10599)
Deprecations and Removals
- No longer build
.deb
packages for Ubuntu 20.10 Groovy Gorilla, which has now EOLed. (#10588) - The
template_dir
configuration settings in thesso
,account_validity
andemail
sections of the configuration file are now deprecated in favour of the globaltemplates.custom_template_directory
setting. See the upgrade notes for more information. (#10596)
Internal Changes
- Improve event caching mechanism to avoid having multiple copies of an event in memory at a time. (#10119)
- Reduce errors in PostgreSQL logs due to concurrent serialization errors. (#10504)
- Include room ID in ignored EDU log messages. Contributed by @ilmari. (#10507)
- Add pagination to the spaces summary based on updates to MSC2946. (#10527, #10530)
- Fix CI to not break when run against branches rather than pull requests. (#10529)
- Mark all events stemming from the MSC2716
/batch_send
endpoint as historical. (#10537) - Clean up some of the federation event authentication code for clarity. (#10539, #10591)
- Convert
Transaction
andEdu
objects to attrs. (#10542) - Update
/batch_send
endpoint to only returnstate_events
created by thestate_events_from_before
passed in. (#10552) - Update contributing.md to warn against rebasing an open PR. (#10563)
- Remove the unused public rooms replication stream. (#10565)
- Clarify error message when failing to join a restricted room. (#10572)
- Remove references to BuildKite in favour of GitHub Actions. (#10573)
- Move
/batch_send
endpoint defined by MSC2716 to the/v2_alpha
directory. (#10576) - Allow multiple custom directories in
read_templates
. (#10587) - Re-organize the
synapse.federation.transport.server
module to create smaller files. (#10590) - Flatten the
synapse.rest.client
package by moving the contents ofv1
andv2_alpha
into the parent. (#10600) - Build Debian packages for Debian 12 (Bookworm). (#10612)
- Fix up a couple of links to the database schema documentation. (#10620)
- Fix a broken link to the upgrade notes. (#10631)
Synapse 1.40.0 (2021-08-10)
No significant changes.
Synapse 1.40.0rc3 (2021-08-09)
Features
- Support MSC3289: room version 8. (#10449)
Bugfixes
Improved Documentation
- Fix broken links in
upgrade.md
. Contributed by @dklimpel. (#10543)
Synapse 1.40.0rc2 (2021-08-04)
Bugfixes
- Fix the
PeriodicallyFlushingMemoryHandler
inhibiting application shutdown because of its background thread. (#10517) - Fix a bug introduced in Synapse v1.40.0rc1 that could cause Synapse to respond with an error when clients would update read receipts. (#10531)
Internal Changes
- Fix release script to open the correct URL for the release. (#10516)
Synapse 1.40.0rc1 (2021-08-03)
Features
- Add support for MSC2033:
device_id
on/account/whoami
. (#9918) - Update support for MSC2716 - Incrementally importing history into existing rooms. (#10245, #10432, #10463)
- Update support for MSC3083 to consider changes in the MSC around which servers can issue join events. (#10254, #10447, #10489)
- Initial support for MSC3244, Room version capabilities over the /capabilities API. (#10283)
- Add a buffered logging handler which periodically flushes itself. (#10407, #10515)
- Add support for https connections to a proxy server. Contributed by @Bubu and @dklimpel. (#10411)
- Support for MSC2285 (hidden read receipts). Contributed by @SimonBrandner. (#10413)
- Email notifications now state whether an invitation is to a room or a space. (#10426)
- Allow setting transaction limit for database connections. (#10440, #10511)
- Add
creation_ts
to "list users" admin API. (#10448)
Bugfixes
- Improve character set detection in URL previews by supporting underscores (in addition to hyphens). Contributed by @srividyut. (#10410)
- Fix events being incorrectly rejected over federation if they reference auth events that the server needed to fetch. (#10439)
- Fix
synapse_federation_server_oldest_inbound_pdu_in_staging
Prometheus metric to not report a max age of 51 years when the queue is empty. (#10455) - Fix a bug which caused an explicit assignment of power-level 0 to a user to be misinterpreted in rare circumstances. (#10499)
Improved Documentation
- Fix hierarchy of providers on the OpenID page. (#10445)
- Consolidate development documentation to
docs/development/
. (#10453) - Add some developer docs to explain room DAG concepts like
outliers
,state_groups
,depth
, etc. (#10464) - Document how to use Complement while developing a new Synapse feature. (#10483)
Internal Changes
- Prune inbound federation queues for a room if they get too large. (#10390)
- Add type hints to
synapse.federation.transport.client
module. (#10408) - Remove shebang line from module files. (#10415)
- Drop backwards-compatibility code that was required to support Ubuntu Xenial. (#10429)
- Use a docker image cache for the prerequisites for the debian package build. (#10431)
- Improve servlet type hints. (#10437, #10438)
- Replace usage of
or_ignore
insimple_insert
withsimple_upsert
usage, to stop spamming postgres logs with spurious ERROR messages. (#10442) - Update the
tests-done
Github Actions status. (#10444, #10512) - Update type annotations to work with forthcoming Twisted 21.7.0 release. (#10446, #10450)
- Cancel redundant GHA workflows when a new commit is pushed. (#10451)
- Mitigate media repo XSS attacks on IE11 via the non-standard X-Content-Security-Policy header. (#10468)
- Additional type hints in the state handler. (#10482)
- Update syntax used to run complement tests. (#10488)
- Fix up type annotations to work with Twisted 21.7. (#10490)
- Improve type annotations for
ObservableDeferred
. (#10491) - Extend release script to also tag and create GitHub releases. (#10496)
- Fix a bug which caused production debian packages to be incorrectly marked as 'prerelease'. (#10500)
Synapse 1.39.0 (2021-07-29)
No significant changes.
Synapse 1.39.0rc3 (2021-07-28)
Bugfixes
- Fix a bug introduced in Synapse 1.38 which caused an exception at startup when SAML authentication was enabled. (#10477)
- Fix a long-standing bug where Synapse would not inform clients that a device had exhausted its one-time-key pool, potentially causing problems decrypting events. (#10485)
- Fix reporting old R30 stats as R30v2 stats. Introduced in v1.39.0rc1. (#10486)
Internal Changes
- Fix an error which prevented the Github Actions workflow to build the docker images from running. (#10461)
- Fix release script to correctly version debian changelog when doing RCs. (#10465)
Synapse 1.39.0rc2 (2021-07-22)
This release also includes the changes in v1.38.1.
Internal Changes
- Move docker image build to Github Actions. (#10416)
Synapse 1.38.1 (2021-07-22)
Bugfixes
- Always include
device_one_time_keys_count
key in/sync
response to work around a bug in Element Android that broke encryption for new devices. (#10457)
Synapse 1.39.0rc1 (2021-07-20)
The Third-Party Event Rules module interface has been deprecated in favour of the generic module interface introduced in Synapse v1.37.0. Support for the old interface is planned to be removed in September 2021. See the upgrade notes for more information.
Features
- Add the ability to override the account validity feature with a module. (#9884)
- The spaces summary API now returns any joinable rooms, not only rooms which are world-readable. (#10298, #10305)
- Add a new version of the R30 phone-home metric, which removes a false impression of retention given by the old R30 metric. (#10332, #10427)
- Allow providing credentials to
http_proxy
. (#10360)
Bugfixes
- Fix error while dropping locks on shutdown. Introduced in v1.38.0. (#10433)
- Add base starting insertion event when no chunk ID is specified in the historical batch send API. (#10250)
- Fix historical batch send endpoint (MSC2716) rejecting batches with messages from multiple senders. (#10276)
- Fix purging rooms that other homeservers are still sending events for. Contributed by @ilmari. (#10317)
- Fix errors during backfill caused by previously purged redaction events. Contributed by Andreas Rammhold (@andir). (#10343)
- Fix the user directory becoming broken (and noisy errors being logged) when knocking and room statistics are in use. (#10344)
- Fix newly added
synapse_federation_server_oldest_inbound_pdu_in_staging
prometheus metric to measure age rather than timestamp. (#10355) - Fix PostgreSQL sometimes using table scans for queries against
state_groups_state
table, taking a long time and a large amount of IO. (#10359) - Fix
make_room_admin
failing for users that have left a private room. (#10367) - Fix a number of logged errors caused by remote servers being down. (#10400, #10414)
- Responses from
/make_{join,leave,knock}
no longer include signatures, which will turn out to be invalid after events are returned to/send_{join,leave,knock}
. (#10404)
Improved Documentation
- Updated installation dependencies for newer macOS versions and ARM Macs. Contributed by Luke Walsh. (#9971)
- Simplify structure of room admin API. (#10313)
- Refresh the logcontext dev documentation. (#10353), (#10337)
- Add delegation example for caddy in the reverse proxy documentation. Contributed by @moritzdietz. (#10368)
- Fix and clarify some links in
docs
andcontrib
. (#10370), (#10322), (#10399) - Make deprecation notice of the spam checker doc more obvious. (#10395)
- Add instructions on installing Debian packages for release candidates. (#10396)
Deprecations and Removals
- Remove functionality associated with the unused
room_stats_historical
anduser_stats_historical
tables. Contributed by @xmunoz. (#9721) - The third-party event rules module interface is deprecated in favour of the generic module interface introduced in Synapse v1.37.0. See the upgrade notes for more information. (#10386)
Internal Changes
- Convert
room_depth.min_depth
column to aBIGINT
. (#10289) - Add tests to characterise the current behaviour of R30 phone-home metrics. (#10315)
- Rebuild event context and auth when processing specific results from
ThirdPartyEventRules
modules. (#10316) - Minor change to the code that populates
user_daily_visits
. (#10324) - Re-enable Sytests that were disabled for the 1.37.1 release. (#10345, #10357)
- Run
pyupgrade
on the codebase. (#10347, #10348) - Switch
application_services_txns.txn_id
database column toBIGINT
. (#10349) - Convert internal type variable syntax to reflect wider ecosystem use. (#10350, #10380, #10381, #10382, #10418)
- Make the Github Actions workflow configuration more efficient. (#10383)
- Add type hints to
get_{domain,localpart}_from_id
. (#10385) - When building Debian packages for prerelease versions, set the Section accordingly. (#10391)
- Add type hints and comments to event auth code. (#10393)
- Stagger sending of presence update to remote servers, reducing CPU spikes caused by starting many connections to remote servers at once. (#10398)
- Remove unused
events_by_room
code (tech debt). (#10421) - Add a github actions job which records success of other jobs. (#10430)
Synapse 1.38.0 (2021-07-13)
This release includes a database schema update which could result in elevated disk usage. See the upgrade notes for more information.
No significant changes since 1.38.0rc3.
Synapse 1.38.0rc3 (2021-07-13)
Internal Changes
Synapse 1.38.0rc2 (2021-07-09)
Bugfixes
- Fix bug where inbound federation in a room could be delayed due to not correctly dropping a lock. Introduced in v1.37.1. (#10336)
Improved Documentation
- Update links to documentation in the sample config. Contributed by @dklimpel. (#10287)
- Fix broken links in INSTALL.md. Contributed by @dklimpel. (#10331)
Synapse 1.38.0rc1 (2021-07-06)
Features
- Implement refresh tokens as specified by MSC2918. (#9450)
- Add support for evicting cache entries based on last access time. (#10205)
- Omit empty fields from the
/sync
response. Contributed by @deepbluev7. (#10214) - Improve validation on federation
send_{join,leave,knock}
endpoints. (#10225, #10243) - Add SSO
external_ids
to the Query User Account admin API. (#10261) - Mark events received over federation which fail a spam check as "soft-failed". (#10263)
- Add metrics for new inbound federation staging area. (#10284)
- Add script to print information about recently registered users. (#10290)
Bugfixes
- Fix a long-standing bug which meant that invite rejections and knocks were not sent out over federation in a timely manner. (#10223)
- Fix a bug introduced in v1.26.0 where only users who have set profile information could be deactivated with erasure enabled. (#10252)
- Fix a long-standing bug where Synapse would return errors after 231 events were handled by the server. (#10264, #10267, #10282, #10286, #10291, #10314, #10326)
- Fix the prometheus
synapse_federation_server_pdu_process_time
metric. Broke in v1.37.1. (#10279) - Ensure that inbound events from federation that were being processed when Synapse was restarted get promptly processed on start up. (#10303)
Improved Documentation
- Move the upgrade notes to docs/upgrade.md and convert them to markdown. (#10166)
- Choose Welcome & Overview as the default page for synapse documentation website. (#10242)
- Adjust the URL in the README.rst file to point to irc.libera.chat. (#10258)
- Fix homeserver config option name in presence router documentation. (#10288)
- Fix link pointing at the wrong section in the modules documentation page. (#10302)
Internal Changes
- Drop
Origin
andAccept
from the value of theAccess-Control-Allow-Headers
response header. (#10114) - Add type hints to the federation servlets. (#10213)
- Improve the reliability of auto-joining remote rooms. (#10237)
- Update the release script to use the semver terminology and determine the release branch based on the next version. (#10239)
- Fix type hints for computing auth events. (#10253)
- Improve the performance of the spaces summary endpoint by only recursing into spaces (and not rooms in general). (#10256)
- Move event authentication methods from
Auth
toEventAuthHandler
. (#10268) - Re-enable a SyTest after it has been fixed. (#10292)
Synapse 1.37.1 (2021-06-30)
This release resolves issues (such as #9490) where one busy room could cause head-of-line blocking, starving Synapse from processing events in other rooms, and causing all federated traffic to fall behind. Synapse 1.37.1 processes inbound federation traffic asynchronously, ensuring that one busy room won't impact others. Please upgrade to Synapse 1.37.1 as soon as possible, in order to increase resilience to other traffic spikes.
No significant changes since v1.37.1rc1.
Synapse 1.37.1rc1 (2021-06-29)
Features
Synapse 1.37.0 (2021-06-29)
This release deprecates the current spam checker interface. See the upgrade notes for more information on how to update to the new generic module interface.
This release also removes support for fetching and renewing TLS certificates using the ACME v1 protocol, which has been fully decommissioned by Let's Encrypt on June 1st 2021. Admins previously using this feature should use a reverse proxy to handle TLS termination, or use an external ACME client (such as certbot) to retrieve a certificate and key and provide them to Synapse using the tls_certificate_path
and tls_private_key_path
configuration settings.
Synapse 1.37.0rc1 (2021-06-24)
Features
- Implement "room knocking" as per MSC2403. Contributed by @Sorunome and anoa. (#6739, #9359, #10167, #10212, #10227)
- Add experimental support for backfilling history into rooms (MSC2716). (#9247)
- Implement a generic interface for third-party plugin modules. (#10062, #10206)
- Implement config option
sso.update_profile_information
to sync SSO users' profile information with the identity provider each time they login. Currently only displayname is supported. (#10108) - Ensure that errors during startup are written to the logs and the console. (#10191)
Bugfixes
- Fix a bug introduced in Synapse v1.25.0 that prevented the
ip_range_whitelist
configuration option from working for federation and identity servers. Contributed by @mikure. (#10115) - Remove a broken import line in Synapse's
admin_cmd
worker. Broke in Synapse v1.33.0. (#10154) - Fix a bug introduced in Synapse v1.21.0 which could cause
/sync
to return immediately with an empty response. (#10157, #10158) - Fix a minor bug in the response to
/_matrix/client/r0/user/{user}/openid/request_token
causingexpires_in
to be a float instead of an integer. Contributed by @lukaslihotzki. (#10175) - Always require users to re-authenticate for dangerous operations: deactivating an account, modifying an account password, and adding 3PIDs. (#10184)
- Fix a bug introduced in Synpase v1.7.2 where remote server count metrics collection would be incorrectly delayed on startup. Found by @heftig. (#10195)
- Fix a bug introduced in Synapse v1.35.1 where an
allow
key of am.room.join_rules
event could be applied for incorrect room versions and configurations. (#10208) - Fix performance regression in responding to user key requests over federation. Introduced in Synapse v1.34.0rc1. (#10221)
Improved Documentation
- Add a new guide to decoding request logs. (#8436)
- Mention in the sample homeserver config that you may need to configure max upload size in your reverse proxy. Contributed by @aaronraimist. (#10122)
- Fix broken links in documentation. (#10180)
- Deploy a snapshot of the documentation website upon each new Synapse release. (#10198)
Deprecations and Removals
- The current spam checker interface is deprecated in favour of a new generic modules system. See the upgrade notes for more information on how to update to the new system. (#10062, #10210, #10238)
- Stop supporting the unstable spaces prefixes from MSC1772. (#10161)
- Remove Synapse's support for automatically fetching and renewing certificates using the ACME v1 protocol. This protocol has been fully turned off by Let's Encrypt for existing installations on June 1st 2021. Admins previously using this feature should use a reverse proxy to handle TLS termination, or use an external ACME client (such as certbot) to retrieve a certificate and key and provide them to Synapse using the
tls_certificate_path
andtls_private_key_path
configuration settings. (#10194)
Internal Changes
- Update the database schema versioning to support gradual migration away from legacy tables. (#9933)
- Add type hints to the federation servlets. (#10080)
- Improve OpenTracing for event persistence. (#10134, #10193)
- Clean up the interface for injecting OpenTracing over HTTP. (#10143)
- Limit the number of in-flight
/keys/query
requests from a single device. (#10144) - Refactor EventPersistenceQueue. (#10145)
- Document
SYNAPSE_TEST_LOG_LEVEL
to see the logger output when running tests. (#10148) - Update the Complement build tags in GitHub Actions to test currently experimental features. (#10155)
- Add a
synapse_federation_soft_failed_events_total
metric to track how often events are soft failed. (#10156) - Fetch the corresponding complement branch when performing CI. (#10160)
- Add some developer documentation about boolean columns in database schemas. (#10164)
- Add extra logging fields to better debug where events are being soft failed. (#10168)
- Add debug logging for when we enter and exit
Measure
blocks. (#10183) - Improve comments in structured logging code. (#10188)
- Update MSC3083 support with modifications from the MSC. (#10189)
- Remove redundant DNS lookup limiter. (#10190)
- Upgrade
black
linting tool to 21.6b0. (#10197) - Expose OpenTracing trace id in response headers. (#10199)
Synapse 1.36.0 (2021-06-15)
No significant changes.
Synapse 1.36.0rc2 (2021-06-11)
Bugfixes
- Fix a bug which caused presence updates to stop working some time after a restart, when using a presence writer worker. Broke in v1.33.0. (#10149)
- Fix a bug when using federation sender worker where it would send out more presence updates than necessary, leading to high resource usage. Broke in v1.33.0. (#10163)
- Fix a bug where Synapse could send the same presence update to a remote twice. (#10165)
Synapse 1.36.0rc1 (2021-06-08)
Features
- Add new endpoint
/_matrix/client/r0/rooms/{roomId}/aliases
from Client-Server API r0.6.1 (previously MSC2432). (#9224) - Improve performance of incoming federation transactions in large rooms. (#9953, #9973)
- Rewrite logic around verifying JSON object and fetching server keys to be more performant and use less memory. (#10035)
- Add new admin APIs for unprotecting local media from quarantine. Contributed by @dklimpel. (#10040)
- Add new admin APIs to remove media by media ID from quarantine. Contributed by @dklimpel. (#10044)
- Make reason and score parameters optional for reporting content. Implements MSC2414. Contributed by Callum Brown. (#10077)
- Add support for routing more requests to workers. (#10084)
- Report OpenTracing spans for database activity. (#10113, #10136, #10141)
- Significantly reduce memory usage of joining large remote rooms. (#10117)
Bugfixes
- Fixed a bug causing replication requests to fail when receiving a lot of events via federation. (#10082)
- Fix a bug in the
force_tracing_for_users
option introduced in Synapse v1.35 which meant that the OpenTracing spans produced were missing most tags. (#10092) - Fixed a bug that could cause Synapse to stop notifying application services. Contributed by Willem Mulder. (#10107)
- Fix bug where the server would attempt to fetch the same history in the room from a remote server multiple times in parallel. (#10116)
- Fix a bug introduced in Synapse 1.33.0 which caused replication requests to fail when receiving a lot of very large events via federation. (#10118)
- Fix bug when using workers where pagination requests failed if a remote server returned zero events from
/backfill
. Introduced in 1.35.0. (#10133)
Improved Documentation
- Clarify security note regarding hosting Synapse on the same domain as other web applications. (#9221)
- Update CAPTCHA documentation to mention turning off the verify origin feature. Contributed by @aaronraimist. (#10046)
- Tweak wording of database recommendation in
INSTALL.md
. Contributed by @aaronraimist. (#10057) - Add initial infrastructure for rendering Synapse documentation with mdbook. (#10086)
- Convert the remaining Admin API documentation files to markdown. (#10089)
- Make a link in docs use HTTPS. Contributed by @RhnSharma. (#10130)
- Fix broken link in Docker docs. (#10132)
Deprecations and Removals
- Remove the experimental
spaces_enabled
flag. The spaces features are always available now. (#10063)
Internal Changes
- Tell CircleCI to build Docker images from
main
branch. (#9906) - Simplify naming convention for release branches to only include the major and minor version numbers. (#10013)
- Add
parse_strings_from_args
for parsing an array from query parameters. (#10048, #10137) - Remove some dead code regarding TLS certificate handling. (#10054)
- Remove redundant, unmaintained
convert_server_keys
script. (#10055) - Improve the error message printed by synctl when synapse fails to start. (#10059)
- Fix GitHub Actions lint for newsfragments. (#10069)
- Update opentracing to inject the right context into the carrier. (#10074)
- Fix up
BatchingQueue
implementation. (#10078) - Log method and path when dropping request due to size limit. (#10091)
- In Github Actions workflows, summarize the Sytest results in an easy-to-read format. (#10094)
- Make
/sync
do fewer state resolutions. (#10102) - Add missing type hints to the admin API servlets. (#10105)
- Improve opentracing annotations for
Notifier
. (#10111) - Enable Prometheus metrics for the jaeger client library. (#10112)
- Work to improve the responsiveness of
/sync
requests. (#10124) - OpenTracing: use a consistent name for background processes. (#10135)
Synapse 1.35.1 (2021-06-03)
Bugfixes
- Fix a bug introduced in v1.35.0 where invite-only rooms would be shown to all users in a space, regardless of if the user had access to it. (#10109)
Synapse 1.35.0 (2021-06-01)
Note that the tag and docker images for v1.35.0rc3
were incorrectly built. If you are experiencing issues with either, it is recommended to upgrade to the equivalent tag or docker image for the v1.35.0
release.
Deprecations and Removals
- The core Synapse development team plan to drop support for the unstable API of MSC2858, including the undocumented
experimental.msc2858_enabled
config option, in August 2021. Client authors should ensure that their clients are updated to use the stable API (which has been supported since Synapse 1.30) well before that time, to give their users time to upgrade. (#10101)
Bugfixes
- Fixed a bug causing replication requests to fail when receiving a lot of events via federation. Introduced in v1.33.0. (#10082)
- Fix HTTP response size limit to allow joining very large rooms over federation. Introduced in v1.33.0. (#10093)
Internal Changes
- Log method and path when dropping request due to size limit. (#10091)
Synapse 1.35.0rc2 (2021-05-27)
Bugfixes
- Fix a bug introduced in v1.35.0rc1 when calling the spaces summary API via a GET request. (#10079)
Synapse 1.35.0rc1 (2021-05-25)
Features
- Add experimental support to allow a user who could join a restricted room to view it in the spaces summary. (#9922, #10007, #10038)
- Reduce memory usage when joining very large rooms over federation. (#9958)
- Add a configuration option which allows enabling opentracing by user id. (#9978)
- Enable experimental support for MSC2946 (spaces summary API) and MSC3083 (restricted join rules) by default. (#10011)
Bugfixes
- Fix a bug introduced in v1.26.0 which meant that
synapse_port_db
would not correctly initialise some postgres sequences, requiring manual updates afterwards. (#9991) - Fix
synctl
's--no-daemonize
parameter to work correctly with worker processes. (#9995) - Fix a validation bug introduced in v1.34.0 in the ordering of spaces in the space summary API. (#10002)
- Fixed deletion of new presence stream states from database. (#10014, #10033)
- Fixed a bug with very high resolution image uploads throwing internal server errors. (#10029)
Updates to the Docker image
- Fix bug introduced in Synapse 1.33.0 which caused a
Permission denied: '/homeserver.log'
error when starting Synapse with the generated log configuration. Contributed by Sergio Miguéns Iglesias. (#10045)
Improved Documentation
- Add hardened systemd files as proposed in #9760 and added them to
contrib/
. Change the docs to reflect the presence of these files. (#9803) - Clarify documentation around SSO mapping providers generating unique IDs and localparts. (#9980)
- Updates to the PostgreSQL documentation (
postgres.md
). (#9988, #9989) - Fix broken link in user directory documentation. Contributed by @junquera. (#10016)
- Add missing room state entry to the table of contents of room admin API. (#10043)
Deprecations and Removals
- Removed support for the deprecated
tls_fingerprints
configuration setting. Contributed by Jerin J Titus. (#9280)
Internal Changes
- Allow sending full presence to users via workers other than the one that called
ModuleApi.send_local_online_presence_to
. (#9823) - Update comments in the space summary handler. (#9974)
- Minor enhancements to the
@cachedList
descriptor. (#9975) - Split multipart email sending into a dedicated handler. (#9977)
- Run
black
on files in thescripts
directory. (#9981) - Add missing type hints to
synapse.util
module. (#9982) - Simplify a few helper functions. (#9984, #9985, #9986)
- Remove unnecessary property from SQLBaseStore. (#9987)
- Remove
keylen
param onLruCache
. (#9993) - Update the Grafana dashboard in
contrib/
. (#10001) - Add a batching queue implementation. (#10017)
- Reduce memory usage when verifying signatures on large numbers of events at once. (#10018)
- Properly invalidate caches for destination retry timings every (instead of expiring entries every 5 minutes). (#10036)
- Fix running complement tests with Synapse workers. (#10039)
- Fix typo in
get_state_ids_for_event
docstring where the return type was incorrect. (#10050)
Synapse 1.34.0 (2021-05-17)
This release deprecates the room_invite_state_types
configuration setting. See the upgrade notes for instructions on updating your configuration file to use the new room_prejoin_state
setting.
This release also deprecates the POST /_synapse/admin/v1/rooms/<room_id>/delete
admin API route. Server administrators are encouraged to update their scripts to use the new DELETE /_synapse/admin/v1/rooms/<room_id>
route instead.
No significant changes since v1.34.0rc1.
Synapse 1.34.0rc1 (2021-05-12)
Features
- Add experimental option to track memory usage of the caches. (#9881)
- Add support for
DELETE /_synapse/admin/v1/rooms/<room_id>
. (#9889) - Add limits to how often Synapse will GC, ensuring that large servers do not end up GC thrashing if
gc_thresholds
has not been correctly set. (#9902) - Improve performance of sending events for worker-based deployments using Redis. (#9905, #9950, #9951)
- Improve performance after joining a large room when presence is enabled. (#9910, #9916)
- Support stable identifiers for MSC1772 Spaces.
m.space.child
events will now be taken into account when populating the experimental spaces summary response. Please see the upgrade notes if you have customisedroom_invite_state_types
in your configuration. (#9915, #9966) - Improve performance of backfilling in large rooms. (#9935)
- Add a config option to allow you to prevent device display names from being shared over federation. Contributed by @aaronraimist. (#9945)
- Update support for MSC2946: Spaces Summary. (#9947, #9954)
Bugfixes
- Fix a bug introduced in v1.32.0 where the associated connection was improperly logged for SQL logging statements. (#9895)
- Correct the type hint for the
user_may_create_room_alias
method of spam checkers. It is provided aRoomAlias
, not astr
. (#9896) - Fix bug where user directory could get out of sync if room visibility and membership changed in quick succession. (#9910)
- Include the
origin_server_ts
property in the experimental MSC2946 support to allow clients to properly sort rooms. (#9928) - Fix bugs introduced in v1.23.0 which made the PostgreSQL port script fail when run with a newly-created SQLite database. (#9930)
- Fix a bug introduced in Synapse 1.29.0 which caused
m.room_key_request
to-device messages sent from one user to another to be dropped. (#9961, #9965) - Fix a bug introduced in v1.27.0 preventing users and appservices exempt from ratelimiting from creating rooms with many invitees. (#9968)
Updates to the Docker image
- Add
startup_delay
to docker healthcheck to reduce waiting time for coming online and update the documentation with extra options. Contributed by @Maquis196. (#9913)
Improved Documentation
- Add
port
argument to the Postgres database sample config section. (#9911)
Deprecations and Removals
- Mark as deprecated
POST /_synapse/admin/v1/rooms/<room_id>/delete
. (#9889)
Internal Changes
- Reduce the length of Synapse's access tokens. (#5588)
- Export jemalloc stats to Prometheus if it is being used. (#9882)
- Add type hints to presence handler. (#9885)
- Reduce memory usage of the LRU caches. (#9886)
- Add type hints to the
synapse.handlers
module. (#9896) - Time response time for external cache requests. (#9904)
- Minor fixes to the
make_full_schema.sh
script. (#9931) - Move database schema files into a common directory. (#9932)
- Add debug logging for lost/delayed to-device messages. (#9959)
Synapse 1.33.2 (2021-05-11)
Due to the security issue highlighted below, server administrators are encouraged to update Synapse. We are not aware of these vulnerabilities being exploited in the wild.
Security advisory
This release fixes a denial of service attack (CVE-2021-29471) against Synapse's push rules implementation. Server admins are encouraged to upgrade.
Internal Changes
- Unpin attrs dependency. (#9946)
Synapse 1.33.1 (2021-05-06)
Bugfixes
- Fix bug where
/sync
would break if using the latest version ofattrs
dependency, by pinning to a previous version. (#9937)
Synapse 1.33.0 (2021-05-05)
Features
- Build Debian packages for Ubuntu 21.04 (Hirsute Hippo). (#9909)
Synapse 1.33.0rc2 (2021-04-29)
Bugfixes
- Fix tight loop when handling presence replication when using workers. Introduced in v1.33.0rc1. (#9900)
Synapse 1.33.0rc1 (2021-04-28)
Features
- Update experimental support for MSC3083: restricting room access via group membership. (#9800, #9814)
- Add experimental support for handling presence on a worker. (#9819, #9820, #9828, #9850)
- Return a new template when an user attempts to renew their account multiple times with the same token, stating that their account is set to expire. This replaces the invalid token template that would previously be shown in this case. This change concerns the optional account validity feature. (#9832)
Bugfixes
- Fixes the OIDC SSO flow when using a
public_baseurl
value including a non-root URL path. (#9726) - Fix thumbnail generation for some sites with non-standard content types. Contributed by @rkfg. (#9788)
- Add some sanity checks to identity server passed to 3PID bind/unbind endpoints. (#9802)
- Limit the size of HTTP responses read over federation. (#9833)
- Fix a bug which could cause Synapse to get stuck in a loop of resyncing device lists. (#9867)
- Fix a long-standing bug where errors from federation did not propagate to the client. (#9868)
Improved Documentation
- Add a note to the docker docs mentioning that we mirror upstream's supported Docker platforms. (#9801)
Internal Changes
- Add a dockerfile for running Synapse in worker-mode under Complement. (#9162)
- Apply
pyupgrade
across the codebase. (#9786) - Move some replication processing out of
generic_worker
. (#9796) - Replace
HomeServer.get_config()
with inline references. (#9815) - Rename some handlers and config modules to not duplicate the top-level module. (#9816)
- Fix a long-standing bug which caused
max_upload_size
to not be correctly enforced. (#9817) - Reduce CPU usage of the user directory by reusing existing calculated room membership. (#9821)
- Small speed up for joining large remote rooms. (#9825)
- Introduce flake8-bugbear to the test suite and fix some of its lint violations. (#9838)
- Only store the raw data in the in-memory caches, rather than objects that include references to e.g. the data stores. (#9845)
- Limit length of accepted email addresses. (#9855)
- Remove redundant
synapse.types.Collection
type definition. (#9856) - Handle recently added rate limits correctly when using
--no-rate-limit
with the demo scripts. (#9858) - Disable invite rate-limiting by default when running the unit tests. (#9871)
- Pass a reactor into
SynapseSite
to make testing easier. (#9874) - Make
DomainSpecificString
anattrs
class. (#9875) - Add type hints to
synapse.api.auth
andsynapse.api.auth_blocking
modules. (#9876) - Remove redundant
_PushHTTPChannel
test class. (#9878) - Remove backwards-compatibility code for Python versions < 3.6. (#9879)
- Small performance improvement around handling new local presence updates. (#9887)
Synapse 1.32.2 (2021-04-22)
This release includes a fix for a regression introduced in 1.32.0.
Bugfixes
- Fix a regression in Synapse 1.32.0 and 1.32.1 which caused
LoggingContext
errors in plugins. (#9857)
Synapse 1.32.1 (2021-04-21)
This release fixes a regression in Synapse 1.32.0 that caused connected Prometheus instances to become unstable.
However, as this release is still subject to the LoggingContext
change in 1.32.0,
it is recommended to remain on or downgrade to 1.31.0.
Bugfixes
- Fix a regression in Synapse 1.32.0 which caused Synapse to report large numbers of Prometheus time series, potentially overwhelming Prometheus instances. (#9854)
Synapse 1.32.0 (2021-04-20)
Note: This release introduces a regression that can overwhelm connected Prometheus instances. This issue was not present in 1.32.0rc1. If affected, it is recommended to downgrade to 1.31.0 in the meantime, and follow these instructions to clean up any excess writeahead logs.
Note: This release also mistakenly included a change that may affected Synapse
modules that import synapse.logging.context.LoggingContext
, such as
synapse-s3-storage-provider.
This will be fixed in a later Synapse version.
Note: This release requires Python 3.6+ and Postgres 9.6+ or SQLite 3.22+.
This release removes the deprecated GET /_synapse/admin/v1/users/<user_id>
admin API. Please use the v2 API instead, which has improved capabilities.
This release requires Application Services to use type m.login.application_service
when registering users via the /_matrix/client/r0/register
endpoint to comply with the spec. Please ensure your Application Services are up to date.
If you are using the packages.matrix.org
Debian repository for Synapse packages,
note that we have recently updated the expiry date on the gpg signing key. If you see an
error similar to The following signatures were invalid: EXPKEYSIG F473DD4473365DE1
, you
will need to get a fresh copy of the keys. You can do so with:
sudo wget -O /usr/share/keyrings/matrix-org-archive-keyring.gpg https://packages.matrix.org/debian/matrix-org-archive-keyring.gpg
Bugfixes
- Fix the log lines of nested logging contexts. Broke in 1.32.0rc1. (#9829)
Synapse 1.32.0rc1 (2021-04-13)
Features
- Add a Synapse module for routing presence updates between users. (#9491)
- Add an admin API to manage ratelimit for a specific user. (#9648)
- Include request information in structured logging output. (#9654)
- Add
order_by
to the admin APIGET /_synapse/admin/v2/users
. Contributed by @dklimpel. (#9691) - Replace the
room_invite_state_types
configuration setting withroom_prejoin_state
. (#9700) - Add experimental support for MSC3083: restricting room access via group membership. (#9717, #9735)
- Update experimental support for Spaces: include
m.room.create
in the room state sent with room-invites. (#9710) - Synapse now requires Python 3.6 or later. It also requires Postgres 9.6 or later or SQLite 3.22 or later. (#9766)
Bugfixes
- Prevent
synapse_forward_extremities
andsynapse_excess_extremity_events
Prometheus metrics from initially reporting zero-values after startup. (#8926) - Fix recently added ratelimits to correctly honour the application service
rate_limited
flag. (#9711) - Fix longstanding bug which caused
duplicate key value violates unique constraint "remote_media_cache_thumbnails_media_origin_media_id_thumbna_key"
errors. (#9725) - Fix bug where sharded federation senders could get stuck repeatedly querying the DB in a loop, using lots of CPU. (#9770)
- Fix duplicate logging of exceptions thrown during federation transaction processing. (#9780)
Updates to the Docker image
- Move opencontainers labels to the final Docker image such that users can inspect them. (#9765)
Improved Documentation
- Make the
allowed_local_3pids
regex example in the sample config stricter. (#9719)
Deprecations and Removals
- Remove old admin API
GET /_synapse/admin/v1/users/<user_id>
. (#9401) - Make
/_matrix/client/r0/register
expect a type ofm.login.application_service
when an Application Service registers a user, to align with the relevant spec. (#9548)
Internal Changes
- Replace deprecated
imp
module with successorimportlib
. Contributed by Cristina Muñoz. (#9718) - Experiment with GitHub Actions for CI. (#9661)
- Introduce flake8-bugbear to the test suite and fix some of its lint violations. (#9682)
- Update
scripts-dev/complement.sh
to use a local checkout of Complement, allow running a subset of tests and have it use Synapse's Complement test blacklist. (#9685) - Improve Jaeger tracing for
to_device
messages. (#9686) - Add release helper script for automating part of the Synapse release process. (#9713)
- Add type hints to expiring cache. (#9730)
- Convert various testcases to
HomeserverTestCase
. (#9736) - Start linting mypy with
no_implicit_optional
. (#9742) - Add missing type hints to federation handler and server. (#9743)
- Check that a
ConfigError
is raised, rather than simplyException
, when appropriate in homeserver config file generation tests. (#9753) - Fix incompatibility with
tox
2.5. (#9769) - Enable Complement tests for MSC2946: Spaces Summary API. (#9771)
- Use mock from the standard library instead of a separate package. (#9772)
- Update Black configuration to target Python 3.6. (#9781)
- Add option to skip unit tests when building Debian packages. (#9793)
Synapse 1.31.0 (2021-04-06)
Note: As announced in v1.25.0, and in line with the deprecation policy for platform dependencies, this is the last release to support Python 3.5 and PostgreSQL 9.5. Future versions of Synapse will require Python 3.6+ and PostgreSQL 9.6+, as per our deprecation policy.
This is also the last release that the Synapse team will be publishing packages for Debian Stretch and Ubuntu Xenial.
Improved Documentation
- Add a document describing the deprecation policy for platform dependencies. (#9723)
Internal Changes
Synapse 1.31.0rc1 (2021-03-30)
Features
- Add support to OpenID Connect login for requiring attributes on the
userinfo
response. Contributed by Hubbe King. (#9609) - Add initial experimental support for a "space summary" API. (#9643, #9652, #9653)
- Add support for the busy presence state as described in MSC3026. (#9644)
- Add support for credentials for proxy authentication in the
HTTPS_PROXY
environment variable. (#9657)
Bugfixes
- Fix a longstanding bug that could cause issues when editing a reply to a message. (#9585)
- Fix the
/capabilities
endpoint to returnm.change_password
as disabled if the local password database is not used for authentication. Contributed by @dklimpel. (#9588) - Check if local passwords are enabled before setting them for the user. (#9636)
- Fix a bug where federation sending can stall due to
concurrent access
database exceptions when it falls behind. (#9639) - Fix a bug introduced in Synapse 1.30.1 which meant the suggested
pip
incantation to install an updatedcryptography
was incorrect. (#9699)
Updates to the Docker image
- Speed up Docker builds and make it nicer to test against Complement while developing (install all dependencies before copying the project). (#9610)
- Include opencontainers labels in the Docker image. (#9612)
Improved Documentation
- Clarify that
register_new_matrix_user
is present also when installed via non-pip package. (#9074) - Update source install documentation to mention platform prerequisites before the source install steps. (#9667)
- Improve worker documentation for fallback/web auth endpoints. (#9679)
- Update the sample configuration for OIDC authentication. (#9695)
Internal Changes
- Preparatory steps for removing redundant
outlier
data fromevent_json.internal_metadata
column. (#9411) - Add type hints to the caching module. (#9442)
- Introduce flake8-bugbear to the test suite and fix some of its lint violations. (#9499, #9659)
- Add additional type hints to the Homeserver object. (#9631, #9638, #9675, #9681)
- Only save remote cross-signing and device keys if they're different from the current ones. (#9634)
- Rename storage function to fix spelling and not conflict with another function's name. (#9637)
- Improve performance of federation catch up by sending the latest events in the room to the remote, rather than just the last event sent by the local server. (#9640, #9664)
- In the
federation_client
commandline client, stop automatically adding the URL prefix, so that servlets on other prefixes can be tested. (#9645) - In the
federation_client
commandline client, handle inlinesigning_key
s inhomeserver.yaml
. (#9647) - Fixed some antipattern issues to improve code quality. (#9649)
- Add a storage method for pulling all current user presence state from the database. (#9650)
- Import
HomeServer
from the proper module. (#9665) - Increase default join ratelimiting burst rate. (#9674)
- Add type hints to third party event rules and visibility modules. (#9676)
- Bump mypy-zope to 0.2.13 to fix "Cannot determine consistent method resolution order (MRO)" errors when running mypy a second time. (#9678)
- Use interpreter from
$PATH
via/usr/bin/env
instead of absolute paths in various scripts. (#9689) - Make it possible to use
dmypy
. (#9692) - Suppress "CryptographyDeprecationWarning: int_from_bytes is deprecated". (#9698)
- Use
dmypy run
in lint script for improved performance in type-checking while developing. (#9701) - Fix undetected mypy error when using Python 3.6. (#9703)
- Fix type-checking CI on develop. (#9709)
Synapse 1.30.1 (2021-03-26)
This release is identical to Synapse 1.30.0, with the exception of explicitly setting a minimum version of Python's Cryptography library to ensure that users of Synapse are protected from the recent OpenSSL security advisories, especially CVE-2021-3449.
Note that Cryptography defaults to bundling its own statically linked copy of OpenSSL, which means that you may not be protected by your operating system's security updates.
It's also worth noting that Cryptography no longer supports Python 3.5, so admins deploying to older environments may not be protected against this or future vulnerabilities. Synapse will be dropping support for Python 3.5 at the end of March.
Updates to the Docker image
- Ensure that the docker container has up to date versions of openssl. (#9697)
Internal Changes
- Enforce that
cryptography
dependency is up to date to ensure it has the most recent openssl patches. (#9697)
Synapse 1.30.0 (2021-03-22)
Note that this release deprecates the ability for appservices to
call POST /_matrix/client/r0/register
without the body parameter type
. Appservice
developers should use a type
value of m.login.application_service
as
per the spec.
In future releases, calling this endpoint with an access token - but without a m.login.application_service
type - will fail.
No significant changes.
Synapse 1.30.0rc1 (2021-03-16)
Features
- Add prometheus metrics for number of users successfully registering and logging in. (#9510, #9511, #9573)
- Add
synapse_federation_last_sent_pdu_time
andsynapse_federation_last_received_pdu_time
prometheus metrics, which monitor federation delays by reporting the timestamps of messages sent and received to a set of remote servers. (#9540) - Add support for generating JSON Web Tokens dynamically for use as OIDC client secrets. (#9549)
- Optimise handling of incomplete room history for incoming federation. (#9601)
- Finalise support for allowing clients to pick an SSO Identity Provider (MSC2858). (#9617)
- Tell spam checker modules about the SSO IdP a user registered through if one was used. (#9626)
Bugfixes
- Fix long-standing bug when generating thumbnails for some images with transparency:
TypeError: cannot unpack non-iterable int object
. (#9473) - Purge chain cover indexes for events that were purged prior to Synapse v1.29.0. (#9542, #9583)
- Fix bug where federation requests were not correctly retried on 5xx responses. (#9567)
- Fix re-activating an account via the admin API when local passwords are disabled. (#9587)
- Fix a bug introduced in Synapse 1.20 which caused incoming federation transactions to stack up, causing slow recovery from outages. (#9597)
- Fix a bug introduced in v1.28.0 where the OpenID Connect callback endpoint could error with a
MacaroonInitException
. (#9620) - Fix Internal Server Error on
GET /_synapse/client/saml2/authn_response
request. (#9623)
Updates to the Docker image
- Make use of an improved malloc implementation (
jemalloc
) in the docker image. (#8553)
Improved Documentation
- Add relayd entry to reverse proxy example configurations. (#9508)
- Improve the SAML2 upgrade notes for 1.27.0. (#9550)
- Link to the "List user's media" admin API from the media admin API docs. (#9571)
- Clarify the spam checker modules documentation example to mention that
parse_config
is a required method. (#9580) - Clarify the sample configuration for
stats
settings. (#9604)
Deprecations and Removals
- The
synapse_federation_last_sent_pdu_age
andsynapse_federation_last_received_pdu_age
prometheus metrics have been removed. They are replaced bysynapse_federation_last_sent_pdu_time
andsynapse_federation_last_received_pdu_time
. (#9540) - Registering an Application Service user without using the
m.login.application_service
login type will be unsupported in an upcoming Synapse release. (#9559)
Internal Changes
- Add tests to ResponseCache. (#9458)
- Add type hints to purge room and server notice admin API. (#9520)
- Add extra logging to ObservableDeferred when callbacks throw exceptions. (#9523)
- Fix incorrect type hints. (#9528, #9543, #9591, #9608, #9618)
- Add an additional test for purging a room. (#9541)
- Add a
.git-blame-ignore-revs
file with the hashes of auto-formatting. (#9560) - Increase the threshold before which outbound federation to a server goes into "catch up" mode, which is expensive for the remote server to handle. (#9561)
- Fix spurious errors reported by the
config-lint.sh
script. (#9562) - Fix type hints and tests for BlacklistingAgentWrapper and BlacklistingReactorWrapper. (#9563)
- Do not have mypy ignore type hints from unpaddedbase64. (#9568)
- Improve efficiency of calculating the auth chain in large rooms. (#9576)
- Convert
synapse.types.Requester
to anattrs
class. (#9586) - Add logging for redis connection setup. (#9590)
- Improve logging when processing incoming transactions. (#9596)
- Remove unused
stats.retention
setting, and emit a warning if stats are disabled. (#9604) - Prevent attempting to bundle aggregations for state events in /context APIs. (#9619)
Synapse 1.29.0 (2021-03-08)
Note that synapse now expects an X-Forwarded-Proto
header when used with a reverse proxy. Please see the upgrade notes for more details on this change.
No significant changes.
Synapse 1.29.0rc1 (2021-03-04)
Features
- Add rate limiters to cross-user key sharing requests. (#8957)
- Add
order_by
to the admin APIGET /_synapse/admin/v1/users/<user_id>/media
. Contributed by @dklimpel. (#8978) - Add some configuration settings to make users' profile data more private. (#9203)
- The
no_proxy
andNO_PROXY
environment variables are now respected in proxied HTTP clients with the lowercase form taking precedence if both are present. Additionally, the lowercasehttps_proxy
environment variable is now respected in proxied HTTP clients on top of existing support for the uppercaseHTTPS_PROXY
form and takes precedence if both are present. Contributed by Timothy Leung. (#9372) - Add a configuration option,
user_directory.prefer_local_users
, which when enabled will make it more likely for users on the same server as you to appear above other users. (#9383, #9385) - Add support for regenerating thumbnails if they have been deleted but the original image is still stored. (#9438)
- Add support for
X-Forwarded-Proto
header when using a reverse proxy. (#9472, #9501, #9512, #9539)
Bugfixes
- Fix a bug where users' pushers were not all deleted when they deactivated their account. (#9285, #9516)
- Fix a bug where a lot of unnecessary presence updates were sent when joining a room. (#9402)
- Fix a bug that caused multiple calls to the experimental
shared_rooms
endpoint to return stale results. (#9416) - Fix a bug in single sign-on which could cause a "No session cookie found" error. (#9436)
- Fix bug introduced in v1.27.0 where allowing a user to choose their own username when logging in via single sign-on did not work unless an
idp_icon
was defined. (#9440) - Fix a bug introduced in v1.26.0 where some sequences were not properly configured when running
synapse_port_db
. (#9449) - Fix deleting pushers when using sharded pushers. (#9465, #9466, #9479, #9536)
- Fix missing startup checks for the consistency of certain PostgreSQL sequences. (#9470)
- Fix a long-standing bug where the media repository could leak file descriptors while previewing media. (#9497)
- Properly purge the event chain cover index when purging history. (#9498)
- Fix missing chain cover index due to a schema delta not being applied correctly. Only affected servers that ran development versions. (#9503)
- Fix a bug introduced in v1.25.0 where
/_synapse/admin/join/
would fail when given a room alias. (#9506) - Prevent presence background jobs from running when presence is disabled. (#9530)
- Fix rare edge case that caused a background update to fail if the server had rejected an event that had duplicate auth events. (#9537)
Improved Documentation
- Update the example systemd config to propagate reloads to individual units. (#9463)
Internal Changes
- Add documentation and type hints to
parse_duration
. (#9432) - Remove vestiges of
uploads_path
configuration setting. (#9462) - Add a comment about systemd-python. (#9464)
- Test that we require validated email for email pushers. (#9496)
- Allow python to generate bytecode for synapse. (#9502)
- Fix incorrect type hints. (#9515, #9518)
- Add type hints to device and event report admin API. (#9519)
- Add type hints to user admin API. (#9521)
- Bump the versions of mypy and mypy-zope used for static type checking. (#9529)
Synapse 1.28.0 (2021-02-25)
Note that this release drops support for ARMv7 in the official Docker images, due to repeated problems building for ARMv7 (and the associated maintenance burden this entails).
This release also fixes the documentation included in v1.27.0 around the callback URI for SAML2 identity providers. If your server is configured to use single sign-on via a SAML2 IdP, you may need to make configuration changes. Please review the upgrade notes for more details on these changes.
Internal Changes
- Revert change in v1.28.0rc1 to remove the deprecated SAML endpoint. (#9474)
Synapse 1.28.0rc1 (2021-02-19)
Removal warning
The v1 list accounts API is deprecated and will be removed in a future release. This API was undocumented and misleading. It can be replaced by the v2 list accounts API, which has been available since Synapse 1.7.0 (2019-12-13).
Please check if you're using any scripts which use the admin API and replace
GET /_synapse/admin/v1/users/<user_id>
with GET /_synapse/admin/v2/users
.
Features
- New admin API to get the context of an event:
/_synapse/admin/rooms/{roomId}/context/{eventId}
. (#9150) - Further improvements to the user experience of registration via single sign-on. (#9300, #9301)
- Add hook to spam checker modules that allow checking file uploads and remote downloads. (#9311)
- Add support for receiving OpenID Connect authentication responses via form
POST
s rather thanGET
s. (#9376) - Add the shadow-banning status to the admin API for user info. (#9400)
Bugfixes
- Fix long-standing bug where sending email notifications would fail for rooms that the server had since left. (#9257)
- Fix bug introduced in Synapse 1.27.0rc1 which meant the "session expired" error page during SSO registration was badly formatted. (#9296)
- Assert a maximum length for some parameters for spec compliance. (#9321, #9393)
- Fix additional errors when previewing URLs: "AttributeError 'NoneType' object has no attribute 'xpath'" and "ValueError: Unicode strings with encoding declaration are not supported. Please use bytes input or XML fragments without declaration.". (#9333)
- Fix a bug causing Synapse to impose the wrong type constraints on fields when processing responses from appservices to
/_matrix/app/v1/thirdparty/user/{protocol}
. (#9361) - Fix bug where Synapse would occasionally stop reconnecting to Redis after the connection was lost. (#9391)
- Fix a long-standing bug when upgrading a room: "TypeError: '>' not supported between instances of 'NoneType' and 'int'". (#9395)
- Reduce the amount of memory used when generating the URL preview of a file that is larger than the
max_spider_size
. (#9421) - Fix a long-standing bug in the deduplication of old presence, resulting in no deduplication. (#9425)
- The
ui_auth.session_timeout
config option can now be specified in terms of number of seconds/minutes/etc/. Contributed by Rishabh Arya. (#9426) - Fix a bug introduced in v1.27.0: "TypeError: int() argument must be a string, a bytes-like object or a number, not 'NoneType." related to the user directory. (#9428)
Updates to the Docker image
- Drop support for ARMv7 in Docker images. (#9433)
Improved Documentation
- Reorganize CHANGELOG.md. (#9281)
- Add note to
auto_join_rooms
config option explaining existing rooms must be publicly joinable. (#9291) - Correct name of Synapse's service file in TURN howto. (#9308)
- Fix the braces in the
oidc_providers
section of the sample config. (#9317) - Update installation instructions on Fedora. (#9322)
- Add HTTP/2 support to the nginx example configuration. Contributed by David Vo. (#9390)
- Update docs for using Gitea as OpenID provider. (#9404)
- Document that pusher instances are shardable. (#9407)
- Fix erroneous documentation from v1.27.0 about updating the SAML2 callback URL. (#9434)
Deprecations and Removals
- Deprecate old admin API
GET /_synapse/admin/v1/users/<user_id>
. (#9429)
Internal Changes
- Fix 'object name reserved for internal use' errors with recent versions of SQLite. (#9003)
- Add experimental support for running Synapse with PyPy. (#9123)
- Deny access to additional IP addresses by default. (#9240)
- Update the
Cursor
type hints to better match PEP 249. (#9299) - Add debug logging for SRV lookups. Contributed by @Bubu. (#9305)
- Improve logging for OIDC login flow. (#9307)
- Share the code for handling required attributes between the CAS and SAML handlers. (#9326)
- Clean up the code to load the metadata for OpenID Connect identity providers. (#9362)
- Convert tests to use
HomeserverTestCase
. (#9377, #9396) - Update the version of black used to 20.8b1. (#9381)
- Allow OIDC config to override discovered values. (#9384)
- Remove some dead code from the acceptance of room invites path. (#9394)
- Clean up an unused method in the presence handler code. (#9408)
Synapse 1.27.0 (2021-02-16)
Note that this release includes a change in Synapse to use Redis as a cache ─ as well as a pub/sub mechanism ─ if Redis support is enabled for workers. No action is needed by server administrators, and we do not expect resource usage of the Redis instance to change dramatically.
This release also changes the callback URI for OpenID Connect (OIDC) and SAML2 identity providers. If your server is configured to use single sign-on via an OIDC/OAuth2 or SAML2 IdP, you may need to make configuration changes. Please review the upgrade notes for more details on these changes.
This release also changes escaping of variables in the HTML templates for SSO or email notifications. If you have customised these templates, please review the upgrade notes for more details on these changes.
Bugfixes
- Fix building Docker images for armv7. (#9405)
Synapse 1.27.0rc2 (2021-02-11)
Features
- Further improvements to the user experience of registration via single sign-on. (#9297)
Bugfixes
- Fix ratelimiting introduced in v1.27.0rc1 for invites to respect the
ratelimit
flag on application services. (#9302) - Do not automatically calculate
public_baseurl
since it can be wrong in some situations. Reverts behaviour introduced in v1.26.0. (#9313)
Improved Documentation
- Clarify the sample configuration for changes made to the template loading code. (#9310)
Synapse 1.27.0rc1 (2021-02-02)
Features
- Add an admin API for getting and deleting forward extremities for a room. (#9062)
- Add an admin API for retrieving the current room state of a room. (#9168)
- Add experimental support for allowing clients to pick an SSO Identity Provider (MSC2858). (#9183, #9242)
- Add an admin API endpoint for shadow-banning users. (#9209)
- Add ratelimits to the 3PID
/requestToken
APIs. (#9238) - Add support to the OpenID Connect integration for adding the user's email address. (#9245)
- Add ratelimits to invites in rooms and to specific users. (#9258)
- Improve the user experience of setting up an account via single-sign on. (#9262, #9272, #9275, #9276, #9277, #9286, #9287)
- Add phone home stats for encrypted messages. (#9283)
- Update the redirect URI for OIDC authentication. (#9288)
Bugfixes
- Fix spurious errors in logs when deleting a non-existant pusher. (#9121)
- Fix a long-standing bug where Synapse would return a 500 error when a thumbnail did not exist (and auto-generation of thumbnails was not enabled). (#9163)
- Fix a long-standing bug where an internal server error was raised when attempting to preview an HTML document in an unknown character encoding. (#9164)
- Fix a long-standing bug where invalid data could cause errors when calculating the presentable room name for push. (#9165)
- Fix bug where we sometimes didn't detect that Redis connections had died, causing workers to not see new data. (#9218)
- Fix a bug where
None
was passed to Synapse modules instead of an empty dictionary if an empty moduleconfig
block was provided in the homeserver config. (#9229) - Fix a bug in the
make_room_admin
admin API where it failed if the admin with the greatest power level was not in the room. Contributed by Pankaj Yadav. (#9235) - Prevent password hashes from getting dropped if a client failed threepid validation during a User Interactive Auth stage. Removes a workaround for an ancient bug in Riot Web <v0.7.4. (#9265)
- Fix single-sign-on when the endpoints are routed to synapse workers. (#9271)
Improved Documentation
- Add docs for using Gitea as OpenID provider. (#9134)
- Add link to Matrix VoIP tester for turn-howto. (#9135)
- Add notes on integrating with Facebook for SSO login. (#9244)
Deprecations and Removals
- The
service_url
parameter incas_config
is deprecated in favor ofpublic_baseurl
. (#9199) - Add new endpoint
/_synapse/client/saml2
for SAML2 authentication callbacks, and deprecate the old endpoint/_matrix/saml2
. (#9289)
Internal Changes
- Add tests to
test_user.UsersListTestCase
for List Users Admin API. (#9045) - Various improvements to the federation client. (#9129)
- Speed up chain cover calculation when persisting a batch of state events at once. (#9176)
- Add a
long_description_type
to the package metadata. (#9180) - Speed up batch insertion when using PostgreSQL. (#9181, #9188)
- Emit an error at startup if different Identity Providers are configured with the same
idp_id
. (#9184) - Improve performance of concurrent use of
StreamIDGenerators
. (#9190) - Add some missing source directories to the automatic linting script. (#9191)
- Precompute joined hosts and store in Redis. (#9198, #9227)
- Clean-up template loading code. (#9200)
- Fix the Python 3.5 old dependencies build. (#9217)
- Update
isort
to v5.7.0 to bypass a bug where it would disagree withblack
about formatting. (#9222) - Add type hints to handlers code. (#9223, #9232)
- Fix Debian package building on Ubuntu 16.04 LTS (Xenial). (#9254)
- Minor performance improvement during TLS handshake. (#9255)
- Refactor the generation of summary text for email notifications. (#9260)
- Restore PyPy compatibility by not calling CPython-specific GC methods when under PyPy. (#9270)
Synapse 1.26.0 (2021-01-27)
This release brings a new schema version for Synapse and rolling back to a previous version is not trivial. Please review the upgrade notes for more details on these changes and for general upgrade guidance.
No significant changes since 1.26.0rc2.
Synapse 1.26.0rc2 (2021-01-25)
Bugfixes
- Fix receipts and account data not being sent down sync. Introduced in v1.26.0rc1. (#9193, #9195)
- Fix chain cover update to handle events with duplicate auth events. Introduced in v1.26.0rc1. (#9210)
Internal Changes
- Add an
oidc-
prefix to anyidp_id
s which are given in theoidc_providers
configuration. (#9189) - Bump minimum
psycopg2
version to v2.8. (#9204)
Synapse 1.26.0rc1 (2021-01-20)
This release brings a new schema version for Synapse and rolling back to a previous version is not trivial. Please review the upgrade notes for more details on these changes and for general upgrade guidance.
Features
- Add support for multiple SSO Identity Providers. (#9015, #9017, #9036, #9067, #9081, #9082, #9105, #9107, #9109, #9110, #9127, #9153, #9154, #9177)
- During user-interactive authentication via single-sign-on, give a better error if the user uses the wrong account on the SSO IdP. (#9091)
- Give the
public_baseurl
a default value, if it is not explicitly set in the configuration file. (#9159) - Improve performance when calculating ignored users in large rooms. (#9024)
- Implement MSC2176 in an experimental room version. (#8984)
- Add an admin API for protecting local media from quarantine. (#9086)
- Remove a user's avatar URL and display name when deactivated with the Admin API. (#8932)
- Update
/_synapse/admin/v1/users/<user_id>/joined_rooms
to work for both local and remote users. (#8948) - Add experimental support for handling to-device messages on worker processes. (#9042, #9043, #9044, #9130)
- Add experimental support for handling
/keys/claim
and/room_keys
APIs on worker processes. (#9068) - Add experimental support for handling
/devices
API on worker processes. (#9092) - Add experimental support for moving off receipts and account data persistence off master. (#9104, #9166)
Bugfixes
- Fix a long-standing issue where an internal server error would occur when requesting a profile over federation that did not include a display name / avatar URL. (#9023)
- Fix a long-standing bug where some caches could grow larger than configured. (#9028)
- Fix error handling during insertion of client IPs into the database. (#9051)
- Fix bug where we didn't correctly record CPU time spent in
on_new_event
block. (#9053) - Fix a minor bug which could cause confusing error messages from invalid configurations. (#9054)
- Fix incorrect exit code when there is an error at startup. (#9059)
- Fix
JSONDecodeError
spamming the logs when sending transactions to remote servers. (#9070) - Fix "Failed to send request" errors when a client provides an invalid room alias. (#9071)
- Fix bugs in federation catchup logic that caused outbound federation to be delayed for large servers after start up. Introduced in v1.8.0 and v1.21.0. (#9114, #9116)
- Fix corruption of
pushers
data when a postgres bouncer is used. (#9117) - Fix minor bugs in handling the
clientRedirectUrl
parameter for SSO login. (#9128) - Fix "Unhandled error in Deferred: BodyExceededMaxSize" errors when .well-known files that are too large. (#9108)
- Fix "UnboundLocalError: local variable 'length' referenced before assignment" errors when the response body exceeds the expected size. This bug was introduced in v1.25.0. (#9145)
- Fix a long-standing bug "ValueError: invalid literal for int() with base 10" when
/publicRooms
is requested with an invalidserver
parameter. (#9161)
Improved Documentation
- Add some extra docs for getting Synapse running on macOS. (#8997)
- Correct a typo in the
systemd-with-workers
documentation. (#9035) - Correct a typo in
INSTALL.md
. (#9040) - Add missing
user_mapping_provider
configuration to the Keycloak OIDC example. Contributed by @chris-ruecker. (#9057) - Quote
pip install
packages when extras are used to avoid shells interpreting bracket characters. (#9151)
Deprecations and Removals
- Remove broken and unmaintained
demo/webserver.py
script. (#9039)
Internal Changes
- Improve efficiency of large state resolutions. (#8868, #9029, #9115, #9118, #9124)
- Various clean-ups to the structured logging and logging context code. (#8939)
- Ensure rejected events get added to some metadata tables. (#9016)
- Ignore date-rotated homeserver logs saved to disk. (#9018)
- Remove an unused column from
access_tokens
table. (#9025) - Add a
-noextras
factor totox.ini
, to support running the tests with no optional dependencies. (#9030) - Fix running unit tests when optional dependencies are not installed. (#9031)
- Allow bumping schema version when using split out state database. (#9033)
- Configure the linters to run on a consistent set of files. (#9038)
- Various cleanups to device inbox store. (#9041)
- Drop unused database tables. (#9055)
- Remove unused
SynapseService
class. (#9058) - Remove unnecessary declarations in the tests for the admin API. (#9063)
- Remove
SynapseRequest.get_user_agent
. (#9069) - Remove redundant
Homeserver.get_ip_from_request
method. (#9080) - Add type hints to media repository. (#9093)
- Fix the wrong arguments being passed to
BlacklistingAgentWrapper
fromMatrixFederationAgent
. Contributed by Timothy Leung. (#9098) - Reduce the scope of caught exceptions in
BlacklistingAgentWrapper
. (#9106) - Improve
UsernamePickerTestCase
. (#9112) - Remove dependency on
distutils
. (#9125) - Enforce that replication HTTP clients are called with keyword arguments only. (#9144)
- Fix the Python 3.5 / old dependencies build in CI. (#9146)
- Replace the old
perspectives
option in the Synapse docker config file template withtrusted_key_servers
. (#9157)
Synapse 1.25.0 (2021-01-13)
Ending Support for Python 3.5 and Postgres 9.5
With this release, the Synapse team is announcing a formal deprecation policy for our platform dependencies, like Python and PostgreSQL:
All future releases of Synapse will follow the upstream end-of-life schedules.
Which means:
- This is the last release which guarantees support for Python 3.5.
- We will end support for PostgreSQL 9.5 early next month.
- We will end support for Python 3.6 and PostgreSQL 9.6 near the end of the year.
Crucially, this means we will not produce .deb packages for Debian 9 (Stretch) or Ubuntu 16.04 (Xenial) beyond the transition period described below.
The website https://endoflife.date/ has convenient summaries of the support schedules for projects like Python and PostgreSQL.
If you are unable to upgrade your environment to a supported version of Python or Postgres, we encourage you to consider using the Synapse Docker images instead.
Transition Period
We will make a good faith attempt to avoid breaking compatibility in all releases through the end of March 2021. However, critical security vulnerabilities in dependencies or other unanticipated circumstances may arise which necessitate breaking compatibility earlier.
We intend to continue producing .deb packages for Debian 9 (Stretch) and Ubuntu 16.04 (Xenial) through the transition period.
Removal warning
The old Purge Room API and Shutdown Room API are deprecated and will be removed in a future release. They will be replaced by the Delete Room API.
POST /_synapse/admin/v1/rooms/<room_id>/delete
replaces POST /_synapse/admin/v1/purge_room
and
POST /_synapse/admin/v1/shutdown_room/<room_id>
.
Bugfixes
- Fix HTTP proxy support when using a proxy that is on a blacklisted IP. Introduced in v1.25.0rc1. Contributed by @Bubu. (#9084)
Synapse 1.25.0rc1 (2021-01-06)
Features
- Add an admin API that lets server admins get power in rooms in which local users have power. (#8756)
- Add optional HTTP authentication to replication endpoints. (#8853)
- Improve the error messages printed as a result of configuration problems for extension modules. (#8874)
- Add the number of local devices to Room Details Admin API. Contributed by @dklimpel. (#8886)
- Add
X-Robots-Tag
header to stop web crawlers from indexing media. Contributed by Aaron Raimist. (#8887) - Spam-checkers may now define their methods as
async
. (#8890) - Add support for allowing users to pick their own user ID during a single-sign-on login. (#8897, #8900, #8911, #8938, #8941, #8942, #8951)
- Add an
email.invite_client_location
configuration option to send a web client location to the invite endpoint on the identity server which allows customisation of the email template. (#8930) - The search term in the list room and list user Admin APIs is now treated as case-insensitive. (#8931)
- Apply an IP range blacklist to push and key revocation requests. (#8821, #8870, #8954)
- Add an option to allow re-use of user-interactive authentication sessions for a period of time. (#8970)
- Allow running the redact endpoint on workers. (#8994)
Bugfixes
- Fix bug where we might not correctly calculate the current state for rooms with multiple extremities. (#8827)
- Fix a long-standing bug in the register admin endpoint (
/_synapse/admin/v1/register
) when themac
field was not provided. The endpoint now properly returns a 400 error. Contributed by @edwargix. (#8837) - Fix a long-standing bug on Synapse instances supporting Single-Sign-On, where users would be prompted to enter their password to confirm certain actions, even though they have not set a password. (#8858)
- Fix a longstanding bug where a 500 error would be returned if the
Content-Length
header was not provided to the upload media resource. (#8862) - Add additional validation to pusher URLs to be compliant with the specification. (#8865)
- Fix the error code that is returned when a user tries to register on a homeserver on which new-user registration has been disabled. (#8867)
- Fix a bug where
PUT /_synapse/admin/v2/users/<user_id>
failed to create a new user whenavatar_url
is specified. Bug introduced in Synapse v1.9.0. (#8872) - Fix a 500 error when attempting to preview an empty HTML file. (#8883)
- Fix occasional deadlock when handling SIGHUP. (#8918)
- Fix login API to not ratelimit application services that have ratelimiting disabled. (#8920)
- Fix bug where we ratelimited auto joining of rooms on registration (using
auto_join_rooms
config). (#8921) - Fix a bug where deactivated users appeared in the user directory when their profile information was updated. (#8933, #8964)
- Fix bug introduced in Synapse v1.24.0 which would cause an exception on startup if both
enabled
andlocaldb_enabled
were set toFalse
in thepassword_config
setting of the configuration file. (#8937) - Fix a bug where 500 errors would be returned if the
m.room_history_visibility
event had invalid content. (#8945) - Fix a bug causing common English words to not be considered for a user directory search. (#8959)
- Fix bug where application services couldn't register new ghost users if the server had reached its MAU limit. (#8962)
- Fix a long-standing bug where a
m.image
event without aurl
would cause errors on push. (#8965) - Fix a small bug in v2 state resolution algorithm, which could also cause performance issues for rooms with large numbers of power levels. (#8971)
- Add validation to the
sendToDevice
API to raise a missing parameters error instead of a 500 error. (#8975) - Add validation of group IDs to raise a 400 error instead of a 500 eror. (#8977)
Improved Documentation
- Fix the "Event persist rate" section of the included grafana dashboard by adding missing prometheus rules. (#8802)
- Combine related media admin API docs. (#8839)
- Fix an error in the documentation for the SAML username mapping provider. (#8873)
- Clarify comments around template directories in
sample_config.yaml
. (#8891) - Move instructions for database setup, adjusted heading levels and improved syntax highlighting in INSTALL.md. Contributed by @fossterer. (#8987)
- Update the example value of
group_creation_prefix
in the sample configuration. (#8992) - Link the Synapse developer room to the development section in the docs. (#9002)
Deprecations and Removals
- Deprecate Shutdown Room and Purge Room Admin APIs. (#8829)
Internal Changes
- Properly store the mapping of external ID to Matrix ID for CAS users. (#8856, #8958)
- Remove some unnecessary stubbing from unit tests. (#8861)
- Remove unused
FakeResponse
class from unit tests. (#8864) - Pass
room_id
toget_auth_chain_difference
. (#8879) - Add type hints to push module. (#8880, #8882, #8901, #8940, #8943, #9020)
- Simplify logic for handling user-interactive-auth via single-sign-on servers. (#8881)
- Skip the SAML tests if the requirements (
pysaml2
andxmlsec1
) aren't available. (#8905) - Fix multiarch docker image builds. (#8906)
- Don't publish
latest
docker image until all archs are built. (#8909) - Various clean-ups to the structured logging and logging context code. (#8916, #8935)
- Automatically drop stale forward-extremities under some specific conditions. (#8929)
- Refactor test utilities for injecting HTTP requests. (#8946)
- Add a maximum size of 50 kilobytes to .well-known lookups. (#8950)
- Fix bug in
generate_log_config
script which made it write empty files. (#8952) - Clean up tox.ini file; disable coverage checking for non-test runs. (#8963)
- Add type hints to the admin and room list handlers. (#8973)
- Add type hints to the receipts and user directory handlers. (#8976)
- Drop the unused
local_invites
table. (#8979) - Add type hints to the base storage code. (#8980)
- Support using PyJWT v2.0.0 in the test suite. (#8986)
- Fix
tests.federation.transport.RoomDirectoryFederationTests
and ensure it runs in CI. (#8998) - Add type hints to the crypto module. (#8999)
Synapse 1.24.0 (2020-12-09)
Due to the two security issues highlighted below, server administrators are encouraged to update Synapse. We are not aware of these vulnerabilities being exploited in the wild.
Security advisory
The following issues are fixed in v1.23.1 and v1.24.0.
-
There is a denial of service attack (CVE-2020-26257) against the federation APIs in which future events will not be correctly sent to other servers over federation. This affects all servers that participate in open federation. (Fixed in #8776).
-
Synapse may be affected by OpenSSL CVE-2020-1971. Synapse administrators should ensure that they have the latest versions of the cryptography Python package installed.
To upgrade Synapse along with the cryptography package:
- Administrators using the
matrix.org
Docker image or the Debian/Ubuntu packages frommatrix.org
should ensure that they have version 1.24.0 or 1.23.1 installed: these images include the updated packages. - Administrators who have installed Synapse from
source
should upgrade the cryptography package within their virtualenv by running:
<path_to_virtualenv>/bin/pip install 'cryptography>=3.3'
- Administrators who have installed Synapse from distribution packages should consult the information from their distributions.
Internal Changes
- Add a maximum version for pysaml2 on Python 3.5. (#8898)
Synapse 1.23.1 (2020-12-09)
Due to the two security issues highlighted below, server administrators are encouraged to update Synapse. We are not aware of these vulnerabilities being exploited in the wild.
Security advisory
The following issues are fixed in v1.23.1 and v1.24.0.
-
There is a denial of service attack (CVE-2020-26257) against the federation APIs in which future events will not be correctly sent to other servers over federation. This affects all servers that participate in open federation. (Fixed in #8776).
-
Synapse may be affected by OpenSSL CVE-2020-1971. Synapse administrators should ensure that they have the latest versions of the cryptography Python package installed.
To upgrade Synapse along with the cryptography package:
- Administrators using the
matrix.org
Docker image or the Debian/Ubuntu packages frommatrix.org
should ensure that they have version 1.24.0 or 1.23.1 installed: these images include the updated packages. - Administrators who have installed Synapse from
source
should upgrade the cryptography package within their virtualenv by running:
<path_to_virtualenv>/bin/pip install 'cryptography>=3.3'
- Administrators who have installed Synapse from distribution packages should consult the information from their distributions.
Bugfixes
- Fix a bug in some federation APIs which could lead to unexpected behaviour if different parameters were set in the URI and the request body. (#8776)
Internal Changes
- Add a maximum version for pysaml2 on Python 3.5. (#8898)
Synapse 1.24.0rc2 (2020-12-04)
Bugfixes
- Fix a regression in v1.24.0rc1 which failed to allow SAML mapping providers which were unable to redirect users to an additional page. (#8878)
Internal Changes
- Add support for the
prometheus_client
newer than 0.9.0. Contributed by Jordan Bancino. (#8875)
Synapse 1.24.0rc1 (2020-12-02)
Features
- Add admin API for logging in as a user. (#8617)
- Allow specification of the SAML IdP if the metadata returns multiple IdPs. (#8630)
- Add support for re-trying generation of a localpart for OpenID Connect mapping providers. (#8801, #8855)
- Allow the
Date
header through CORS. Contributed by Nicolas Chamo. (#8804) - Add a config option,
push.group_by_unread_count
, which controls whether unread message counts in push notifications are defined as "the number of rooms with unread messages" or "total unread messages". (#8820) - Add
force_purge
option to delete-room admin api. (#8843)
Bugfixes
- Fix a bug where appservices may be sent an excessive amount of read receipts and presence. Broke in v1.22.0. (#8744)
- Fix a bug in some federation APIs which could lead to unexpected behaviour if different parameters were set in the URI and the request body. (#8776)
- Fix a bug where synctl could spawn duplicate copies of a worker. Contributed by Waylon Cude. (#8798)
- Allow per-room profiles to be used for the server notice user. (#8799)
- Fix a bug where logging could break after a call to SIGHUP. (#8817)
- Fix
register_new_matrix_user
failing with "Bad Request" when trailing slash is included in server URL. Contributed by @angdraug. (#8823) - Fix a minor long-standing bug in login, where we would offer the
password
login type if a custom auth provider supported it, even if password login was disabled. (#8835) - Fix a long-standing bug which caused Synapse to require unspecified parameters during user-interactive authentication. (#8848)
- Fix a bug introduced in v1.20.0 where the user-agent and IP address reported during user registration for CAS, OpenID Connect, and SAML were of the wrong form. (#8784)
Improved Documentation
- Clarify the usecase for a msisdn delegate. Contributed by Adrian Wannenmacher. (#8734)
- Remove extraneous comma from JSON example in User Admin API docs. (#8771)
- Update
turn-howto.md
with troubleshooting notes. (#8779) - Fix the example on how to set the
Content-Type
header in nginx for the Client Well-Known URI. (#8793) - Improve the documentation for the admin API to list all media in a room with respect to encrypted events. (#8795)
- Update the formatting of the
push
section of the homeserver config file to better align with the code style guidelines. (#8818) - Improve documentation how to configure prometheus for workers. (#8822)
- Update example prometheus console. (#8824)
Deprecations and Removals
- Remove old
/_matrix/client/*/admin
endpoints which were deprecated since Synapse 1.20.0. (#8785) - Disable pretty printing JSON responses for curl. Users who want pretty-printed output should use jq in combination with curl. Contributed by @tulir. (#8833)
Internal Changes
- Simplify the way the
HomeServer
object caches its internal attributes. (#8565, #8851) - Add an example and documentation for clock skew to the SAML2 sample configuration to allow for clock/time difference between the homserver and IdP. Contributed by @localguru. (#8731)
- Generalise
RoomMemberHandler._locally_reject_invite
to apply to more flows than just invite. (#8751) - Generalise
RoomStore.maybe_store_room_on_invite
to handle other, non-invite membership events. (#8754) - Refactor test utilities for injecting HTTP requests. (#8757, #8758, #8759, #8760, #8761, #8777)
- Consolidate logic between the OpenID Connect and SAML code. (#8765)
- Use
TYPE_CHECKING
instead of magicMYPY
variable. (#8770) - Add a commandline script to sign arbitrary json objects. (#8772)
- Minor log line improvements for the SSO mapping code used to generate Matrix IDs from SSO IDs. (#8773)
- Add additional error checking for OpenID Connect and SAML mapping providers. (#8774, #8800)
- Add type hints to HTTP abstractions. (#8806, #8812)
- Remove unnecessary function arguments and add typing to several membership replication classes. (#8809)
- Optimise the lookup for an invite from another homeserver when trying to reject it. (#8815)
- Add tests for
password_auth_provider
s. (#8819) - Drop redundant database index on
event_json
. (#8845) - Simplify
uk.half-shot.msc2778.login.application_service
login handler. (#8847) - Refactor
password_auth_provider
support code. (#8849) - Add missing
ordering
to background database updates. (#8850) - Allow for specifying a room version when creating a room in unit tests via
RestHelper.create_room_as
. (#8854)
Synapse 1.23.0 (2020-11-18)
This release changes the way structured logging is configured. See the upgrade notes for details.
Note: We are aware of a trivially exploitable denial of service vulnerability in versions of Synapse prior to 1.20.0. Complete details will be disclosed on Monday, November 23rd. If you have not upgraded recently, please do so.
Bugfixes
- Fix a dependency versioning bug in the Dockerfile that prevented Synapse from starting. (#8767)
Synapse 1.23.0rc1 (2020-11-13)
Features
- Add a push rule that highlights when a jitsi conference is created in a room. (#8286)
- Add an admin api to delete a single file or files that were not used for a defined time from server. Contributed by @dklimpel. (#8519)
- Split admin API for reported events (
GET /_synapse/admin/v1/event_reports
) into detail and list endpoints. This is a breaking change to #8217 which was introduced in Synapse v1.21.0. Those who already use this API should check their scripts. Contributed by @dklimpel. (#8539) - Support generating structured logs via the standard logging configuration. (#8607, #8685)
- Add an admin API to allow server admins to list users' pushers. Contributed by @dklimpel. (#8610, #8689)
- Add an admin API
GET /_synapse/admin/v1/users/<user_id>/media
to get information about uploaded media. Contributed by @dklimpel. (#8647) - Add an admin API for local user media statistics. Contributed by @dklimpel. (#8700)
- Add
displayname
to Shared-Secret Registration for admins. (#8722)
Bugfixes
- Fix fetching of E2E cross signing keys over federation when only one of the master key and device signing key is cached already. (#8455)
- Fix a bug where Synapse would blindly forward bad responses from federation to clients when retrieving profile information. (#8580)
- Fix a bug where the account validity endpoint would silently fail if the user ID did not have an expiration time. It now returns a 400 error. (#8620)
- Fix email notifications for invites without local state. (#8627)
- Fix handling of invalid group IDs to return a 400 rather than log an exception and return a 500. (#8628)
- Fix handling of User-Agent headers that are invalid UTF-8, which caused user agents of users to not get correctly recorded. (#8632)
- Fix a bug in the
joined_rooms
admin API if the user has never joined any rooms. The bug was introduced, along with the API, in v1.21.0. (#8643) - Fix exception during handling multiple concurrent requests for remote media when using multiple media repositories. (#8682)
- Fix bug that prevented Synapse from recovering after losing connection to the database. (#8726)
- Fix bug where the
/_synapse/admin/v1/send_server_notice
API could send notices to non-notice rooms. (#8728) - Fix PostgreSQL port script fails when DB has no backfilled events. Broke in v1.21.0. (#8729)
- Fix PostgreSQL port script to correctly handle foreign key constraints. Broke in v1.21.0. (#8730)
- Fix PostgreSQL port script so that it can be run again after a failure. Broke in v1.21.0. (#8755)
Improved Documentation
- Instructions for Azure AD in the OpenID Connect documentation. Contributed by peterk. (#8582)
- Improve the sample configuration for single sign-on providers. (#8635)
- Fix the filepath of Dex's example config and the link to Dex's Getting Started guide in the OpenID Connect docs. (#8657)
- Note support for Python 3.9. (#8665)
- Minor updates to docs on running tests. (#8666)
- Interlink prometheus/grafana documentation. (#8667)
- Notes on SSO logins and media_repository worker. (#8701)
- Document experimental support for running multiple event persisters. (#8706)
- Add information regarding the various sources of, and expected contributions to, Synapse's documentation to
CONTRIBUTING.md
. (#8714) - Migrate documentation
docs/admin_api/event_reports
to markdown. (#8742) - Add some helpful hints to the README for new Synapse developers. Contributed by @chagai95. (#8746)
Internal Changes
- Optimise
/createRoom
with multiple invited users. (#8559) - Implement and use an
@lru_cache
decorator. (#8595) - Don't instansiate Requester directly. (#8614)
- Type hints for
RegistrationStore
. (#8615) - Change schema to support access tokens belonging to one user but granting access to another. (#8616)
- Remove unused OPTIONS handlers. (#8621)
- Run
mypy
as part of the lint.sh script. (#8633) - Correct Synapse's PyPI package name in the OpenID Connect installation instructions. (#8634)
- Catch exceptions during initialization of
password_providers
. Contributed by Nicolai Søborg. (#8636) - Fix typos and spelling errors in the code. (#8639)
- Reduce number of OpenTracing spans started. (#8640, #8668, #8670)
- Add field
total
to device list in admin API. (#8644) - Add more type hints to the application services code. (#8655, #8693)
- Tell Black to format code for Python 3.5. (#8664)
- Don't pull event from DB when handling replication traffic. (#8669)
- Abstract some invite-related code in preparation for landing knocking. (#8671, #8688)
- Clarify representation of events in logfiles. (#8679)
- Don't require
hiredis
package to be installed to run unit tests. (#8680) - Fix typing info on cache call signature to accept
on_invalidate
. (#8684) - Fail tests if they do not await coroutines. (#8690)
- Improve start time by adding an index to
e2e_cross_signing_keys.stream_id
. (#8694) - Re-organize the structured logging code to separate the TCP transport handling from the JSON formatting. (#8697)
- Use Python 3.8 in Docker images by default. (#8698)
- Remove the "draft" status of the Room Details Admin API. (#8702)
- Improve the error returned when a non-string displayname or avatar_url is used when updating a user's profile. (#8705)
- Block attempts by clients to send server ACLs, or redactions of server ACLs, that would result in the local server being blocked from the room. (#8708)
- Add metrics the allow the local sysadmin to track 3PID
/requestToken
requests. (#8712) - Consolidate duplicated lists of purged tables that are checked in tests. (#8713)
- Add some
mdui:UIInfo
element examples forsaml2_config
in the homeserver config. (#8718) - Improve the error message returned when a remote server incorrectly sets the
Content-Type
header in response to a JSON request. (#8719) - Speed up repeated state resolutions on the same room by caching event ID to auth event ID lookups. (#8752)
Synapse 1.22.1 (2020-10-30)
Bugfixes
- Fix a bug where an appservice may not be forwarded events for a room it was recently invited to. Broke in v1.22.0. (#8676)
- Fix
Object of type frozendict is not JSON serializable
exceptions when using third-party event rules. Broke in v1.22.0. (#8678)
Synapse 1.22.0 (2020-10-27)
No significant changes.
Synapse 1.22.0rc2 (2020-10-26)
Bugfixes
- Fix bugs where ephemeral events were not sent to appservices. Broke in v1.22.0rc1. (#8648, #8656)
- Fix
user_daily_visits
table to not have duplicate rows per user/device due to multiple user agents. Broke in v1.22.0rc1. (#8654)
Synapse 1.22.0rc1 (2020-10-22)
Features
- Add a configuration option for always using the "userinfo endpoint" for OpenID Connect. This fixes support for some identity providers, e.g. GitLab. Contributed by Benjamin Koch. (#7658)
- Add ability for
ThirdPartyEventRules
modules to query and manipulate whether a room is in the public rooms directory. (#8292, #8467) - Add support for olm fallback keys (MSC2732). (#8312, #8501)
- Add support for running background tasks in a separate worker process. (#8369, #8458, #8489, #8513, #8544, #8599)
- Add support for device dehydration (MSC2697). (#8380)
- Add support for MSC2409, which allows sending typing, read receipts, and presence events to appservices. (#8437, #8590)
- Change default room version to "6", per MSC2788. (#8461)
- Add the ability to send non-membership events into a room via the
ModuleApi
. (#8479) - Increase default upload size limit from 10M to 50M. Contributed by @Akkowicz. (#8502)
- Add support for modifying event content in
ThirdPartyRules
modules. (#8535, #8564)
Bugfixes
- Fix a longstanding bug where invalid ignored users in account data could break clients. (#8454)
- Fix a bug where backfilling a room with an event that was missing the
redacts
field would break. (#8457) - Don't attempt to respond to some requests if the client has already disconnected. (#8465)
- Fix message duplication if something goes wrong after persisting the event. (#8476)
- Fix incremental sync returning an incorrect
prev_batch
token in timeline section, which when used to paginate returned events that were included in the incremental sync. Broken since v0.16.0. (#8486) - Expose the
uk.half-shot.msc2778.login.application_service
to clients from the login API. This feature was added in v1.21.0, but was not exposed as a potential login flow. (#8504) - Fix error code for
/profile/{userId}/displayname
to beM_BAD_JSON
. (#8517) - Fix a bug introduced in v1.7.0 that could cause Synapse to insert values from non-state
m.room.retention
events into theroom_retention
database table. (#8527) - Fix not sending events over federation when using sharded event writers. (#8536)
- Fix a long standing bug where email notifications for encrypted messages were blank. (#8545)
- Fix increase in the number of
There was no active span...
errors logged when using OpenTracing. (#8567) - Fix a bug that prevented errors encountered during execution of the
synapse_port_db
from being correctly printed. (#8585) - Fix appservice transactions to only include a maximum of 100 persistent and 100 ephemeral events. (#8606)
Updates to the Docker image
- Added multi-arch support (arm64,arm/v7) for the docker images. Contributed by @maquis196. (#7921)
- Add support for passing commandline args to the synapse process. Contributed by @samuel-p. (#8390)
Improved Documentation
- Update the directions for using the manhole with coroutines. (#8462)
- Improve readme by adding new shield.io badges. (#8493)
- Added note about docker in manhole.md regarding which ip address to bind to. Contributed by @Maquis196. (#8526)
- Document the new behaviour of the
allowed_lifetime_min
andallowed_lifetime_max
settings in the room retention configuration. (#8529)
Deprecations and Removals
- Drop unused
device_max_stream_id
table. (#8589)
Internal Changes
- Check for unreachable code with mypy. (#8432)
- Add unit test for event persister sharding. (#8433)
- Allow events to be sent to clients sooner when using sharded event persisters. (#8439, #8488, #8496, #8499)
- Configure
public_baseurl
when using demo scripts. (#8443) - Add SQL logging on queries that happen during startup. (#8448)
- Speed up unit tests when using PostgreSQL. (#8450)
- Remove redundant database loads of stream_ordering for events we already have. (#8452)
- Reduce inconsistencies between codepaths for membership and non-membership events. (#8463)
- Combine
SpamCheckerApi
with the more genericModuleApi
. (#8464) - Additional testing for
ThirdPartyEventRules
. (#8468) - Add
-d
option to./scripts-dev/lint.sh
to lint files that have changed since the last git commit. (#8472) - Unblacklist some sytests. (#8474)
- Include the log level in the phone home stats. (#8477)
- Remove outdated sphinx documentation, scripts and configuration. (#8480)
- Clarify error message when plugin config parsers raise an error. (#8492)
- Remove the deprecated
Handlers
object. (#8494) - Fix a threadsafety bug in unit tests. (#8497)
- Add user agent to user_daily_visits table. (#8503)
- Add type hints to various parts of the code base. (#8407, #8505, #8507, #8547, #8562, #8609)
- Remove unused code from the test framework. (#8514)
- Apply some internal fixes to the
HomeServer
class to make its code more idiomatic and statically-verifiable. (#8515) - Factor out common code between
RoomMemberHandler._locally_reject_invite
andEventCreationHandler.create_event
. (#8537) - Improve database performance by executing more queries without starting transactions. (#8542)
- Rename
Cache
toDeferredCache
, to better reflect its purpose. (#8548) - Move metric registration code down into
LruCache
. (#8561, #8591) - Replace
DeferredCache
with the lighter-weightLruCache
where possible. (#8563) - Add virtualenv-generated folders to
.gitignore
. (#8566) - Add
get_immediate
method toDeferredCache
. (#8568) - Fix mypy not properly checking across the codebase, additionally, fix a typing assertion error in
handlers/auth.py
. (#8569) - Fix
synmark
benchmark runner. (#8571) - Modify
DeferredCache.get()
to returnDeferred
s instead ofObservableDeferred
s. (#8572) - Adjust a protocol-type definition to fit
sqlite3
assertions. (#8577) - Support macOS on the
synmark
benchmark runner. (#8578) - Update
mypy
static type checker to 0.790. (#8583, #8600) - Re-organize the structured logging code to separate the TCP transport handling from the JSON formatting. (#8587)
- Remove extraneous unittest logging decorators from unit tests. (#8592)
- Minor optimisations in caching code. (#8593, #8594)
Synapse 1.21.2 (2020-10-15)
Debian packages and Docker images have been rebuilt using the latest versions of dependency libraries, including authlib 0.15.1. Please see bugfixes below.
Security advisory
-
HTML pages served via Synapse were vulnerable to cross-site scripting (XSS) attacks. All server administrators are encouraged to upgrade. (#8444) (CVE-2020-26891)
This fix was originally included in v1.21.0 but was missing a security advisory.
This was reported by Denis Kasak.
Bugfixes
- Fix rare bug where sending an event would fail due to a racey assertion. (#8530)
- An updated version of the authlib dependency is included in the Docker and Debian images to fix an issue using OpenID Connect. See #8534 for details.
Synapse 1.21.1 (2020-10-13)
This release fixes a regression in v1.21.0 that prevented debian packages from being built. It is otherwise identical to v1.21.0.
Synapse 1.21.0 (2020-10-12)
No significant changes since v1.21.0rc3.
As noted in
v1.20.0,
a future release will drop support for accessing Synapse's
Admin API under the
/_matrix/client/*
endpoint prefixes. At that point, the Admin API will only
be accessible under /_synapse/admin
.
Synapse 1.21.0rc3 (2020-10-08)
Bugfixes
- Fix duplication of events on high traffic servers, caused by PostgreSQL
could not serialize access due to concurrent update
errors. (#8456)
Internal Changes
- Add Groovy Gorilla to the list of distributions we build
.deb
s for. (#8475)
Synapse 1.21.0rc2 (2020-10-02)
Features
- Convert additional templates from inline HTML to Jinja2 templates. (#8444)
Bugfixes
- Fix a regression in v1.21.0rc1 which broke thumbnails of remote media. (#8438)
- Do not expose the experimental
uk.half-shot.msc2778.login.application_service
flow in the login API, which caused a compatibility problem with Element iOS. (#8440) - Fix malformed log line in new federation "catch up" logic. (#8442)
- Fix DB query on startup for negative streams which caused long start up times. Introduced in #8374. (#8447)
Synapse 1.21.0rc1 (2020-10-01)
Features
- Require the user to confirm that their password should be reset after clicking the email confirmation link. (#8004)
- Add an admin API
GET /_synapse/admin/v1/event_reports
to read entries of tableevent_reports
. Contributed by @dklimpel. (#8217) - Consolidate the SSO error template across all configuration. (#8248, #8405)
- Add a configuration option to specify a whitelist of domains that a user can be redirected to after validating their email or phone number. (#8275, #8417)
- Add experimental support for sharding event persister. (#8294, #8387, #8396, #8419)
- Add the room topic and avatar to the room details admin API. (#8305)
- Add an admin API for querying rooms where a user is a member. Contributed by @dklimpel. (#8306)
- Add
uk.half-shot.msc2778.login.application_service
login type to allow appservices to login. (#8320) - Add a configuration option that allows existing users to log in with OpenID Connect. Contributed by @BBBSnowball and @OmmyZhang. (#8345)
- Add prometheus metrics for replication requests. (#8406)
- Support passing additional single sign-on parameters to the client. (#8413)
- Add experimental reporting of metrics on expensive rooms for state-resolution. (#8420)
- Add experimental prometheus metric to track numbers of "large" rooms for state resolutiom. (#8425)
- Add prometheus metrics to track federation delays. (#8430)
Bugfixes
- Fix a bug in the media repository where remote thumbnails with the same size but different crop methods would overwrite each other. Contributed by @deepbluev7. (#7124)
- Fix inconsistent handling of non-existent push rules, and stop tracking the
enabled
state of removed push rules. (#7796) - Fix a longstanding bug when storing a media file with an empty
upload_name
. (#7905) - Fix messages not being sent over federation until an event is sent into the same room. (#8230, #8247, #8258, #8272, #8322)
- Fix a longstanding bug where files that could not be thumbnailed would result in an Internal Server Error. (#8236, #8435)
- Upgrade minimum version of
canonicaljson
to version 1.4.0, to fix an unicode encoding issue. (#8262) - Fix longstanding bug which could lead to incomplete database upgrades on SQLite. (#8265)
- Fix stack overflow when stderr is redirected to the logging system, and the logging system encounters an error. (#8268)
- Fix a bug which cause the logging system to report errors, if
DEBUG
was enabled and nocontext
filter was applied. (#8278) - Fix edge case where push could get delayed for a user until a later event was pushed. (#8287)
- Fix fetching malformed events from remote servers. (#8324)
- Fix
UnboundLocalError
from occuring when appservices send a malformed register request. (#8329) - Don't send push notifications to expired user accounts. (#8353)
- Fix a regression in v1.19.0 with reactivating users through the admin API. (#8362)
- Fix a bug where during device registration the length of the device name wasn't limited. (#8364)
- Include
guest_access
in the fields that are checked for null bytes when updatingroom_stats_state
. Broke in v1.7.2. (#8373) - Fix theoretical race condition where events are not sent down
/sync
if the synchrotron worker is restarted without restarting other workers. (#8374) - Fix a bug which could cause errors in rooms with malformed membership events, on servers using sqlite. (#8385)
- Fix "Re-starting finished log context" warning when receiving an event we already had over federation. (#8398)
- Fix incorrect handling of timeouts on outgoing HTTP requests. (#8400)
- Fix a regression in v1.20.0 in the
synapse_port_db
script regarding theui_auth_sessions_ips
table. (#8410) - Remove unnecessary 3PID registration check when resetting password via an email address. Bug introduced in v0.34.0rc2. (#8414)
Improved Documentation
- Add
/_synapse/client
to the reverse proxy documentation. (#8227) - Add note to the reverse proxy settings documentation about disabling Apache's mod_security2. Contributed by Julian Fietkau (@jfietkau). (#8375)
- Improve description of
server_name
config option inhomserver.yaml
. (#8415)
Deprecations and Removals
- Drop support for
prometheus_client
older than 0.4.0. (#8426)
Internal Changes
- Fix tests on distros which disable TLSv1.0. Contributed by @danc86. (#8208)
- Simplify the distributor code to avoid unnecessary work. (#8216)
- Remove the
populate_stats_process_rooms_2
background job and restore functionality topopulate_stats_process_rooms
. (#8243) - Clean up type hints for
PaginationConfig
. (#8250, #8282) - Track the latest event for every destination and room for catch-up after federation outage. (#8256)
- Fix non-user visible bug in implementation of
MultiWriterIdGenerator.get_current_token_for_writer
. (#8257) - Switch to the JSON implementation from the standard library. (#8259)
- Add type hints to
synapse.util.async_helpers
. (#8260) - Simplify tests that mock asynchronous functions. (#8261)
- Add type hints to
StreamToken
andRoomStreamToken
classes. (#8279) - Change
StreamToken.room_key
to be aRoomStreamToken
instance. (#8281) - Refactor notifier code to correctly use the max event stream position. (#8288)
- Use slotted classes where possible. (#8296)
- Support testing the local Synapse checkout against the Complement homeserver test suite. (#8317)
- Update outdated usages of
metaclass
to python 3 syntax. (#8326) - Move lint-related dependencies to package-extra field, update CONTRIBUTING.md to utilise this. (#8330, #8377)
- Use the
admin_patterns
helper in additional locations. (#8331) - Fix test logging to allow braces in log output. (#8335)
- Remove
__future__
imports related to Python 2 compatibility. (#8337) - Simplify
super()
calls to Python 3 syntax. (#8344) - Fix bad merge from
release-v1.20.0
branch todevelop
. (#8354) - Factor out a
_send_dummy_event_for_room
method. (#8370) - Improve logging of state resolution. (#8371)
- Add type annotations to
SimpleHttpClient
. (#8372) - Refactor ID generators to use
async with
syntax. (#8383) - Add
EventStreamPosition
type. (#8388) - Create a mechanism for marking tests "logcontext clean". (#8399)
- A pair of tiny cleanups in the federation request code. (#8401)
- Add checks on startup that PostgreSQL sequences are consistent with their associated tables. (#8402)
- Do not include appservice users when calculating the total MAU for a server. (#8404)
- Typing fixes for
synapse.handlers.federation
. (#8422) - Various refactors to simplify stream token handling. (#8423)
- Make stream token serializing/deserializing async. (#8427)
Synapse 1.20.1 (2020-09-24)
Bugfixes
- Fix a bug introduced in v1.20.0 which caused the
synapse_port_db
script to fail. (#8386) - Fix a bug introduced in v1.20.0 which caused variables to be incorrectly escaped in Jinja2 templates. (#8394)
Synapse 1.20.0 (2020-09-22)
No significant changes since v1.20.0rc5.
Removal warning
Historically, the Synapse Admin
API has been
accessible under the /_matrix/client/api/v1/admin
,
/_matrix/client/unstable/admin
, /_matrix/client/r0/admin
and
/_synapse/admin
prefixes. In a future release, we will be dropping support
for accessing Synapse's Admin API using the /_matrix/client/*
prefixes.
From that point, the Admin API will only be accessible under /_synapse/admin
.
This makes it easier for homeserver admins to lock down external access to the
Admin API endpoints.
Synapse 1.20.0rc5 (2020-09-18)
In addition to the below, Synapse 1.20.0rc5 also includes the bug fix that was included in 1.19.3.
Features
- Add flags to the
/versions
endpoint for whether new rooms default to using E2EE. (#8343)
Bugfixes
- Fix rate limiting of federation
/send
requests. (#8342) - Fix a longstanding bug where back pagination over federation could get stuck if it failed to handle a received event. (#8349)
Internal Changes
Synapse 1.19.3 (2020-09-18)
Bugfixes
- Partially mitigate bug where newly joined servers couldn't get past events in a room when there is a malformed event. (#8350)
Synapse 1.20.0rc4 (2020-09-16)
Synapse 1.20.0rc4 is identical to 1.20.0rc3, with the addition of the security fix that was included in 1.19.2.
Synapse 1.19.2 (2020-09-16)
Due to the issue below server admins are encouraged to upgrade as soon as possible.
Bugfixes
- Fix joining rooms over federation that include malformed events. (#8324)
Synapse 1.20.0rc3 (2020-09-11)
Bugfixes
- Fix a bug introduced in v1.20.0rc1 where the wrong exception was raised when invalid JSON data is encountered. (#8291)
Synapse 1.20.0rc2 (2020-09-09)
Bugfixes
- Fix a bug introduced in v1.20.0rc1 causing some features related to notifications to misbehave following the implementation of unread counts. (#8280)
Synapse 1.20.0rc1 (2020-09-08)
Removal warning
Some older clients used a disallowed character (:
) in the client_secret
parameter of various endpoints. The incorrect behaviour was allowed for backwards compatibility, but is now being removed from Synapse as most users have updated their client. Further context can be found at #6766.
Features
- Add an endpoint to query your shared rooms with another user as an implementation of MSC2666. (#7785)
- Iteratively encode JSON to avoid blocking the reactor. (#8013, #8116)
- Add support for shadow-banning users (ignoring any message send requests). (#8034, #8092, #8095, #8142, #8152, #8157, #8158, #8176)
- Use the default template file when its equivalent is not found in a custom template directory. (#8037, #8107, #8252)
- Add unread messages count to sync responses, as specified in MSC2654. (#8059, #8254, #8270, #8274)
- Optimise
/federation/v1/user/devices/
API by only returning devices with encryption keys. (#8198)
Bugfixes
- Fix a memory leak by limiting the length of time that messages will be queued for a remote server that has been unreachable. (#7864)
- Fix
Re-starting finished log context PUT-nnnn
warning when event persistence failed. (#8081) - Synapse now correctly enforces the valid characters in the
client_secret
parameter used in various endpoints. (#8101) - Fix a bug introduced in v1.7.2 impacting message retention policies that would allow federated homeservers to dictate a retention period that's lower than the configured minimum allowed duration in the configuration file. (#8104)
- Fix a long-standing bug where invalid JSON would be accepted by Synapse. (#8106)
- Fix a bug introduced in Synapse v1.12.0 which could cause
/sync
requests to fail with a 404 if you had a very old outstanding room invite. (#8110) - Return a proper error code when the rooms of an invalid group are requested. (#8129)
- Fix a bug which could cause a leaked postgres connection if synapse was set to daemonize. (#8131)
- Clarify the error code if a user tries to register with a numeric ID. This bug was introduced in v1.15.0. (#8135)
- Fix a bug where appservices with ratelimiting disabled would still be ratelimited when joining rooms. This bug was introduced in v1.19.0. (#8139)
- Fix logging in via OpenID Connect with a provider that uses integer user IDs. (#8190)
- Fix a longstanding bug where user directory updates could break when unexpected profile data was included in events. (#8223)
- Fix a longstanding bug where stats updates could break when unexpected profile data was included in events. (#8226)
- Fix slow start times for large servers by removing a table scan of the
users
table from startup code. (#8271)
Updates to the Docker image
- Fix builds of the Docker image on non-x86 platforms. (#8144)
- Added curl for healthcheck support and readme updates for the change. Contributed by @maquis196. (#8147)
Improved Documentation
- Link to matrix-synapse-rest-password-provider in the password provider documentation. (#8111)
- Updated documentation to note that Synapse does not follow
HTTP 308
redirects due to an upstream library not supporting them. Contributed by Ryan Cole. (#8120) - Explain better what GDPR-erased means when deactivating a user. (#8189)
Internal Changes
- Add filter
name
to the/users
admin API, which filters by user ID or displayname. Contributed by Awesome Technologies Innovationslabor GmbH. (#7377, #8163) - Reduce run times of some unit tests by advancing the reactor a fewer number of times. (#7757)
- Don't fail
/submit_token
requests on incorrect session ID ifrequest_token_inhibit_3pid_errors
is turned on. (#7991) - Convert various parts of the codebase to async/await. (#8071, #8072, #8074, #8075, #8076, #8087, #8100, #8119, #8121, #8133, #8156, #8162, #8166, #8168, #8173, #8191, #8192, #8193, #8194, #8195, #8197, #8199, #8200, #8201, #8202, #8207, #8213, #8214)
- Remove some unused database functions. (#8085)
- Add type hints to various parts of the codebase. (#8090, #8127, #8187, #8241, #8140, #8183, #8232, #8235, #8237, #8244)
- Return the previous stream token if a non-member event is a duplicate. (#8093, #8112)
- Separate
get_current_token
into two since there are two different use cases for it. (#8113) - Remove
ChainedIdGenerator
. (#8123) - Reduce the amount of whitespace in JSON stored and sent in responses. (#8124)
- Update the test federation client to handle streaming responses. (#8130)
- Micro-optimisations to
get_auth_chain_ids
. (#8132) - Refactor
StreamIdGenerator
andMultiWriterIdGenerator
to have the same interface. (#8161) - Add functions to
MultiWriterIdGen
used by events stream. (#8164, #8179) - Fix tests that were broken due to the merge of 1.19.1. (#8167)
- Make
SlavedIdTracker.advance
have the same interface asMultiWriterIDGenerator
. (#8171) - Remove unused
is_guest
parameter from, and add safeguard to,MessageHandler.get_room_data
. (#8174, #8181) - Standardize the mypy configuration. (#8175)
- Refactor some of
LoginRestServlet
's helper methods, and move them toAuthHandler
for easier reuse. (#8182) - Fix
wait_for_stream_position
to allow multiple waiters on same stream ID. (#8196) - Make
MultiWriterIDGenerator
work for streams that use negative values. (#8203) - Refactor queries for device keys and cross-signatures. (#8204, #8205, #8222, #8224, #8225, #8231, #8233, #8234)
- Fix type hints for functions decorated with
@cached
. (#8240) - Remove obsolete
order
field from federation send queues. (#8245) - Stop sub-classing from object. (#8249)
- Add more logging to debug slow startup. (#8264)
- Do not attempt to upgrade database schema on worker processes. (#8266, #8276)
Synapse 1.19.1 (2020-08-27)
No significant changes.
Synapse 1.19.1rc1 (2020-08-25)
Bugfixes
- Fix a bug introduced in v1.19.0 where appservices with ratelimiting disabled would still be ratelimited when joining rooms. (#8139)
- Fix a bug introduced in v1.19.0 that would cause e.g. profile updates to fail due to incorrect application of rate limits on join requests. (#8153)
Synapse 1.19.0 (2020-08-17)
No significant changes since 1.19.0rc1.
Removal warning
As outlined in the previous release,
we are no longer publishing Docker images with the -py3
tag suffix. On top of that, we have also removed the
latest-py3
tag. Please see
the announcement in the upgrade notes for 1.18.0.
Synapse 1.19.0rc1 (2020-08-13)
Features
- Add option to allow server admins to join rooms which fail complexity checks. Contributed by @lugino-emeritus. (#7902)
- Add an option to purge room or not with delete room admin endpoint (
POST /_synapse/admin/v1/rooms/<room_id>/delete
). Contributed by @dklimpel. (#7964) - Add rate limiting to users joining rooms. (#8008)
- Add a
/health
endpoint to every configured HTTP listener that can be used as a health check endpoint by load balancers. (#8048) - Allow login to be blocked based on the values of SAML attributes. (#8052)
- Allow guest access to the
GET /_matrix/client/r0/rooms/{room_id}/members
endpoint, according to MSC2689. Contributed by Awesome Technologies Innovationslabor GmbH. (#7314)
Bugfixes
- Fix a bug introduced in Synapse v1.7.2 which caused inaccurate membership counts in the room directory. (#7977)
- Fix a long standing bug: 'Duplicate key value violates unique constraint "event_relations_id"' when message retention is configured. (#7978)
- Fix "no create event in auth events" when trying to reject invitation after inviter leaves. Bug introduced in Synapse v1.10.0. (#7980)
- Fix various comments and minor discrepencies in server notices code. (#7996)
- Fix a long standing bug where HTTP HEAD requests resulted in a 400 error. (#7999)
- Fix a long-standing bug which caused two copies of some log lines to be written when synctl was used along with a MemoryHandler logger. (#8011, #8012)
Updates to the Docker image
- We no longer publish Docker images with the
-py3
tag suffix, as announced in the upgrade notes. (#8056)
Improved Documentation
- Document how to set up a client .well-known file and fix several pieces of outdated documentation. (#7899)
- Improve workers docs. (#7990, #8000)
- Fix typo in
docs/workers.md
. (#7992) - Add documentation for how to undo a room shutdown. (#7998, #8010)
Internal Changes
- Reduce the amount of whitespace in JSON stored and sent in responses. Contributed by David Vo. (#7372)
- Switch to the JSON implementation from the standard library and bump the minimum version of the canonicaljson library to 1.2.0. (#7936, #7979)
- Convert various parts of the codebase to async/await. (#7947, #7948, #7949, #7951, #7963, #7973, #7975, #7976, #7981, #7987, #7989, #8003, #8014, #8016, #8027, #8031, #8032, #8035, #8042, #8044, #8045, #8061, #8062, #8063, #8066, #8069, #8070)
- Move some database-related log lines from the default logger to the database/transaction loggers. (#7952)
- Add a script to detect source code files using non-unix line terminators. (#7965, #7970)
- Log the SAML session ID during creation. (#7971)
- Implement new experimental push rules for some users. (#7997)
- Remove redundant and unreliable signature check for v1 Identity Service lookup responses. (#8001)
- Improve the performance of the register endpoint. (#8009)
- Reduce less useful output in the newsfragment CI step. Add a link to the changelog section of the contributing guide on error. (#8024)
- Rename storage layer objects to be more sensible. (#8033)
- Change the default log config to reduce disk I/O and storage for new servers. (#8040)
- Add an assertion on
prev_events
increate_new_client_event
. (#8041) - Add a comment to
ServerContextFactory
about the use ofSSLv23_METHOD
. (#8043) - Log
OPTIONS
requests atDEBUG
rather thanINFO
level to reduce amount logged atINFO
. (#8049) - Reduce amount of outbound request logging at
INFO
level. (#8050) - It is no longer necessary to explicitly define
filters
in the logging configuration. (Continuing to do so is redundant but harmless.) (#8051) - Add and improve type hints. (#8058, #8064, #8060, #8067)
Synapse 1.18.0 (2020-07-30)
Deprecation Warnings
Docker Tags with -py3
Suffix
From 10th August 2020, we will no longer publish Docker images with the -py3
tag suffix. The images tagged with the -py3
suffix have been identical to the non-suffixed tags since release 0.99.0, and the suffix is obsolete.
On 10th August, we will remove the latest-py3
tag. Existing per-release tags (such as v1.18.0-py3
) will not be removed, but no new -py3
tags will be added.
Scripts relying on the -py3
suffix will need to be updated.
TCP-based Replication
When setting up worker processes, we now recommend the use of a Redis server for replication. The old direct TCP connection method is deprecated and will be removed in a future release. See docs/workers.md for more details.
Improved Documentation
- Update worker docs with latest enhancements. (#7969)
Synapse 1.18.0rc2 (2020-07-28)
Bugfixes
- Fix an
AssertionError
exception introduced in v1.18.0rc1. (#7876) - Fix experimental support for moving typing off master when worker is restarted, which is broken in v1.18.0rc1. (#7967)
Internal Changes
- Further optimise queueing of inbound replication commands. (#7876)
Synapse 1.18.0rc1 (2020-07-27)
Features
- Include room states on invite events that are sent to application services. Contributed by @Sorunome. (#6455)
- Add delete room admin endpoint (
POST /_synapse/admin/v1/rooms/<room_id>/delete
). Contributed by @dklimpel. (#7613, #7953) - Add experimental support for running multiple federation sender processes. (#7798)
- Add the option to validate the
iss
andaud
claims for JWT logins. (#7827) - Add support for handling registration requests across multiple client reader workers. (#7830)
- Add an admin API to list the users in a room. Contributed by Awesome Technologies Innovationslabor GmbH. (#7842)
- Allow email subjects to be customised through Synapse's configuration. (#7846)
- Add the ability to re-activate an account from the admin API. (#7847, #7908)
- Add experimental support for running multiple pusher workers. (#7855)
- Add experimental support for moving typing off master. (#7869, #7959)
- Report CPU metrics to prometheus for time spent processing replication commands. (#7879)
- Support oEmbed for media previews. (#7920)
- Abort federation requests where the client disconnects before the ratelimiter expires. (#7930)
- Cache responses to
/_matrix/federation/v1/state_ids
to reduce duplicated work. (#7931)
Bugfixes
- Fix detection of out of sync remote device lists when receiving events from remote users. (#7815)
- Fix bug where Synapse fails to process an incoming event over federation if the server is missing too much of the event's auth chain. (#7817)
- Fix a bug causing Synapse to misinterpret the value
off
forencryption_enabled_by_default_for_room_type
in its configuration file(s) if that value isn't surrounded by quotes. This bug was introduced in v1.16.0. (#7822) - Fix bug where we did not always pass in
app_name
orserver_name
to email templates, including e.g. for registration emails. (#7829) - Errors which occur while using the non-standard JWT login now return the proper error:
403 Forbidden
with an error code ofM_FORBIDDEN
. (#7844) - Fix "AttributeError: 'str' object has no attribute 'get'" error message when applying per-room message retention policies. The bug was introduced in Synapse 1.7.0. (#7850)
- Fix a bug introduced in Synapse 1.10.0 which could cause a "no create event in auth events" error during room creation. (#7854)
- Fix a bug which allowed empty rooms to be rejoined over federation. (#7859)
- Fix 'Unable to find a suitable guest user ID' error when using multiple client_reader workers. (#7866)
- Fix a long standing bug where the tracing of async functions with opentracing was broken. (#7872, #7961)
- Fix "TypeError in
synapse.notifier
" exceptions. (#7880) - Fix deprecation warning due to invalid escape sequences. (#7895)
Updates to the Docker image
- Base docker image on Debian Buster rather than Alpine Linux. Contributed by @maquis196. (#7839)
Improved Documentation
- Provide instructions on using
register_new_matrix_user
via docker. (#7885) - Change the sample config postgres user section to use
synapse_user
instead ofsynapse
to align with the documentation. (#7889) - Reorder database paragraphs to promote postgres over sqlite. (#7933)
- Update the dates of ACME v1's end of life in
ACME.md
. (#7934)
Deprecations and Removals
- Remove unused
synapse_replication_tcp_resource_invalidate_cache
prometheus metric. (#7878) - Remove Ubuntu Eoan from the list of
.deb
packages that we build as it is now end-of-life. Contributed by @gary-kim. (#7888)
Internal Changes
- Switch parts of the codebase from
simplejson
to the standard libraryjson
. (#7802) - Add type hints to the http server code and remove an unused parameter. (#7813)
- Add type hints to synapse.api.errors module. (#7820)
- Ensure that calls to
json.dumps
are compatible with the standard library json. (#7836) - Remove redundant
retry_on_integrity_error
wrapper for event persistence code. (#7848) - Consistently use
db_to_json
to convert from database values to JSON objects. (#7849) - Convert various parts of the codebase to async/await. (#7851, #7860, #7868, #7871, #7873, #7874, #7884, #7912, #7935, #7939, #7942, #7944)
- Add support for handling registration requests across multiple client reader workers. (#7853)
- Small performance improvement in typing processing. (#7856)
- The default value of
filter_timeline_limit
was changed from -1 (no limit) to 100. (#7858) - Optimise queueing of inbound replication commands. (#7861)
- Add some type annotations to
HomeServer
andBaseHandler
. (#7870) - Clean up
PreserveLoggingContext
. (#7877) - Change "unknown room version" logging from 'error' to 'warning'. (#7881)
- Stop using
device_max_stream_id
table and just usedevice_inbox.stream_id
. (#7882) - Return an empty body for OPTIONS requests. (#7886)
- Fix typo in generated config file. Contributed by @ThiefMaster. (#7890)
- Import ABC from
collections.abc
for Python 3.10 compatibility. (#7892) - Remove unused functions
time_function
,trace_function
,get_previous_frames
andget_previous_frame
fromsynapse.logging.utils
module. (#7897) - Lint the
contrib/
directory in CI and linting scripts, addsynctl
to the linting script for consistency with CI. (#7914) - Use Element CSS and logo in notification emails when app name is Element. (#7919)
- Optimisation to /sync handling: skip serializing the response if the client has already disconnected. (#7927)
- When a client disconnects, don't log it as 'Error processing request'. (#7928)
- Add debugging to
/sync
response generation (disabled by default). (#7929) - Update comments that refer to Deferreds for async functions. (#7945)
- Simplify error handling in federation handler. (#7950)
Synapse 1.17.0 (2020-07-13)
Synapse 1.17.0 is identical to 1.17.0rc1, with the addition of the fix that was included in 1.16.1.
Synapse 1.16.1 (2020-07-10)
In some distributions of Synapse 1.16.0, we incorrectly included a database migration which added a new, unused table. This release removes the redundant table.
Bugfixes
- Drop table
local_rejections_stream
which was incorrectly added in Synapse 1.16.0. (#7816, b1beb3ff5)
Synapse 1.17.0rc1 (2020-07-09)
Bugfixes
- Fix inconsistent handling of upper and lower case in email addresses when used as identifiers for login, etc. Contributed by @dklimpel. (#7021)
- Fix "Tried to close a non-active scope!" error messages when opentracing is enabled. (#7732)
- Fix incorrect error message when database CTYPE was set incorrectly. (#7760)
- Fix to not ignore
set_tweak
actions in Push Rules that have novalue
, as permitted by the specification. (#7766) - Fix synctl to handle empty config files correctly. Contributed by @kotovalexarian. (#7779)
- Fixes a long standing bug in worker mode where worker information was saved in the devices table instead of the original IP address and user agent. (#7797)
- Fix 'stuck invites' which happen when we are unable to reject a room invite received over federation. (#7804, #7809, #7810)
Updates to the Docker image
- Include libwebp in the Docker file to properly handle webp image uploads. (#7791)
Improved Documentation
- Improve the documentation of the non-standard JSON web token login type. (#7776)
- Update doc links for caddy. Contributed by Nicolai Søborg. (#7789)
Internal Changes
- Refactor getting replication updates from database. (#7740)
- Send push notifications with a high or low priority depending upon whether they may generate user-observable effects. (#7765)
- Use symbolic names for replication stream names. (#7768)
- Add early returns to
_check_for_soft_fail
. (#7769) - Fix up
synapse.handlers.federation
to pass mypy. (#7770) - Convert the appserver handler to async/await. (#7775)
- Allow to use higher versions of prometheus_client <0.9.0 which are expected to introduce no breaking changes. Contributed by Oliver Kurz. (#7780)
- Update linting scripts and codebase to be compatible with
isort
v5. (#7786) - Stop populating unused table
local_invites
. (#7793) - Ensure that strings (not bytes) are passed into JSON serialization. (#7799)
- Switch from simplejson to the standard library json. (#7800)
- Add
signing_key
property toHomeServer
to save code duplication. (#7805) - Improve stacktraces from exceptions in background processes. (#7808)
- Fix various spelling errors in comments and log lines. (#7811)
Synapse 1.16.0 (2020-07-08)
No significant changes since 1.16.0rc2.
Note that this release deprecates the m.login.jwt
login method, renaming it
to org.matrix.login.jwt
, as m.login.jwt
is not part of the Matrix spec.
Otherwise the behaviour is identical. Synapse will accept both names for now,
but this may change in a future release.
Synapse 1.16.0rc2 (2020-07-02)
Synapse 1.16.0rc2 includes the security fixes released with Synapse 1.15.2. Please see below for more details.
Improved Documentation
- Update postgres image in example
docker-compose.yaml
to tag12-alpine
. (#7696)
Internal Changes
- Add some metrics for inbound and outbound federation latencies:
synapse_federation_server_pdu_process_time
andsynapse_event_processing_lag_by_event
. (#7771)
Synapse 1.15.2 (2020-07-02)
Due to the two security issues highlighted below, server administrators are encouraged to update Synapse. We are not aware of these vulnerabilities being exploited in the wild.
Security advisory
-
A malicious homeserver could force Synapse to reset the state in a room to a small subset of the correct state. This affects all Synapse deployments which federate with untrusted servers. (96e9afe6)
-
HTML pages served via Synapse were vulnerable to clickjacking attacks. This predominantly affects homeservers with single-sign-on enabled, but all server administrators are encouraged to upgrade. (ea26e9a9)
This was reported by Quentin Gliech.
Synapse 1.16.0rc1 (2020-07-01)
Features
- Add an option to enable encryption by default for new rooms. (#7639)
- Add support for running multiple media repository workers. See docs/workers.md for instructions. (#7706)
- Media can now be marked as safe from quarantined. (#7718)
- Expand the configuration options for auto-join rooms. (#7763)
Bugfixes
- Remove
user_id
from the response toGET /_matrix/client/r0/presence/{userId}/status
to match the specification. (#7606) - In worker mode, ensure that replicated data has not already been received. (#7648)
- Fix intermittent exception during startup, introduced in Synapse 1.14.0. (#7663)
- Include a user-agent for federation and well-known requests. (#7677)
- Accept the proper field (
phone
) for them.id.phone
identifier type. The legacy field ofnumber
is still accepted as a fallback. Bug introduced in v0.20.0. (#7687) - Fix "Starting db txn 'get_completed_ui_auth_stages' from sentinel context" warning. The bug was introduced in 1.13.0. (#7688)
- Compare the URI and method during user interactive authentication (instead of the URI twice). Bug introduced in 1.13.0. (#7689)
- Fix a long standing bug where the response to the
GET room_keys/version
endpoint had the incorrect type for theetag
field. (#7691) - Fix logged error during device resync in opentracing. Broke in v1.14.0. (#7698)
- Do not break push rule evaluation when receiving an event with a non-string body. This is a long-standing bug. (#7701)
- Fixs a long standing bug which resulted in an exception: "TypeError: argument of type 'ObservableDeferred' is not iterable". (#7708)
- The
synapse_port_db
script no longer fails when theui_auth_sessions
table is non-empty. This bug has existed since v1.13.0. (#7711) - Synapse will now fetch media from the proper specified URL (using the r0 prefix instead of the unspecified v1). (#7714)
- Fix the tables ignored by
synapse_port_db
to be in sync the current database schema. (#7717) - Fix missing
Content-Length
on HTTP responses from the metrics handler. (#7730) - Fix large state resolutions from stalling Synapse for seconds at a time. (#7735, #7746)
Improved Documentation
- Spelling correction in sample_config.yaml. (#7652)
- Added instructions for how to use Keycloak via OpenID Connect to authenticate with Synapse. (#7659)
- Corrected misspelling of PostgreSQL. (#7724)
Deprecations and Removals
- Deprecate
m.login.jwt
login method in favour oforg.matrix.login.jwt
, asm.login.jwt
is not part of the Matrix spec. (#7675)
Internal Changes
- Refactor getting replication updates from database. (#7636)
- Clean-up the login fallback code. (#7657)
- Increase the default SAML session expiry time to 15 minutes. (#7664)
- Convert the device message and pagination handlers to async/await. (#7678)
- Convert typing handler to async/await. (#7679)
- Require
parameterized
package version to be at least 0.7.0. (#7680) - Refactor handling of
listeners
configuration settings. (#7681) - Replace uses of
six.iterkeys
/iteritems
/itervalues
withkeys()
/items()
/values()
. (#7692) - Add support for using
rust-python-jaeger-reporter
library to reduce jaeger tracing overhead. (#7697) - Make Tox actions work on Debian 10. (#7703)
- Replace all remaining uses of
six
with native Python 3 equivalents. Contributed by @ilmari. (#7704) - Fix broken link in sample config. (#7712)
- Speed up state res v2 across large state differences. (#7725)
- Convert directory handler to async/await. (#7727)
- Move
flake8
to the end ofscripts-dev/lint.sh
as it takes the longest and could cause the script to exit early. (#7738) - Explain the "test" conditional requirement for dependencies is not all of the modules necessary to run the unit tests. (#7751)
- Add some metrics for inbound and outbound federation latencies:
synapse_federation_server_pdu_process_time
andsynapse_event_processing_lag_by_event
. (#7755)
Synapse 1.15.1 (2020-06-16)
Bugfixes
- Fix a bug introduced in v1.15.0 that would crash Synapse on start when using certain password auth providers. (#7684)
- Fix a bug introduced in v1.15.0 which meant that some 3PID management endpoints were not accessible on the correct URL. (#7685)
Synapse 1.15.0 (2020-06-11)
No significant changes.
Synapse 1.15.0rc1 (2020-06-09)
Features
- Advertise support for Client-Server API r0.6.0 and remove related unstable feature flags. (#6585)
- Add an option to disable autojoining rooms for guest accounts. (#6637)
- For SAML authentication, add the ability to pass email addresses to be added to new users' accounts via SAML attributes. Contributed by Christopher Cooper. (#7385)
- Add admin APIs to allow server admins to manage users' devices. Contributed by @dklimpel. (#7481)
- Add support for generating thumbnails for WebP images. Previously, users would see an empty box instead of preview image. Contributed by @WGH-. (#7586)
- Support the standardized
m.login.sso
user-interactive authentication flow. (#7630)
Bugfixes
- Allow new users to be registered via the admin API even if the monthly active user limit has been reached. Contributed by @dklimpel. (#7263)
- Fix email notifications not being enabled for new users when created via the Admin API. (#7267)
- Fix str placeholders in an instance of
PrepareDatabaseException
. Introduced in Synapse v1.8.0. (#7575) - Fix a bug in automatic user creation during first time login with
m.login.jwt
. Regression in v1.6.0. Contributed by @olof. (#7585) - Fix a bug causing the cross-signing keys to be ignored when resyncing a device list. (#7594)
- Fix metrics failing when there is a large number of active background processes. (#7597)
- Fix bug where returning rooms for a group would fail if it included a room that the server was not in. (#7599)
- Fix duplicate key violation when persisting read markers. (#7607)
- Prevent an entire iteration of the device list resync loop from failing if one server responds with a malformed result. (#7609)
- Fix exceptions when fetching events from a remote host fails. (#7622)
- Make
synctl restart
start synapse if it wasn't running. (#7624) - Pass device information through to the login endpoint when using the login fallback. (#7629)
- Advertise the
m.login.token
login flow when OpenID Connect is enabled. (#7631) - Fix bug in account data replication stream. (#7656)
Improved Documentation
- Update the OpenBSD installation instructions. (#7587)
- Advertise Python 3.8 support in
setup.py
. (#7602) - Add a link to
#synapse:matrix.org
in the troubleshooting section of the README. (#7603) - Clarifications to the admin api documentation. (#7647)
Internal Changes
- Convert the identity handler to async/await. (#7561)
- Improve query performance for fetching state from a PostgreSQL database. Contributed by @ilmari. (#7567)
- Speed up processing of federation stream RDATA rows. (#7584)
- Add comment to systemd example to show postgresql dependency. (#7591)
- Refactor
Ratelimiter
to limit the amount of expensive config value accesses. (#7595) - Convert groups handlers to async/await. (#7600)
- Clean up exception handling in
SAML2ResponseResource
. (#7614) - Check that all asynchronous tasks succeed and general cleanup of
MonthlyActiveUsersTestCase
andTestMauLimit
. (#7619) - Convert
get_user_id_by_threepid
to async/await. (#7620) - Switch to upstream
dh-virtualenv
rather than our fork for Debian package builds. (#7621) - Update CI scripts to check the number in the newsfile fragment. (#7623)
- Check if the localpart of a Matrix ID is reserved for guest users earlier in the registration flow, as well as when responding to requests to
/register/available
. (#7625) - Minor cleanups to OpenID Connect integration. (#7628)
- Attempt to fix flaky test:
PhoneHomeStatsTestCase.test_performance_100
. (#7634) - Fix typos of
m.olm.curve25519-aes-sha2
andm.megolm.v1.aes-sha2
in comments, test files. (#7637) - Convert user directory, state deltas, and stats handlers to async/await. (#7640)
- Remove some unused constants. (#7644)
- Fix type information on
assert_*_is_admin
methods. (#7645) - Convert registration handler to async/await. (#7649)
Synapse 1.14.0 (2020-05-28)
No significant changes.
Synapse 1.14.0rc2 (2020-05-27)
Bugfixes
- Fix cache config to not apply cache factor to event cache. Regression in v1.14.0rc1. (#7578)
- Fix bug where
ReplicationStreamer
was not always started when replication was enabled. Bug introduced in v1.14.0rc1. (#7579) - Fix specifying individual cache factors for caches with special characters in their name. Regression in v1.14.0rc1. (#7580)
Improved Documentation
- Fix the OIDC
client_auth_method
value in the sample config. (#7581)
Synapse 1.14.0rc1 (2020-05-26)
Features
- Synapse's cache factor can now be configured in
homeserver.yaml
by thecaches.global_factor
setting. Additionally,caches.per_cache_factors
controls the cache factors for individual caches. (#6391) - Add OpenID Connect login/registration support. Contributed by Quentin Gliech, on behalf of les Connecteurs. (#7256, #7457)
- Add room details admin endpoint. Contributed by Awesome Technologies Innovationslabor GmbH. (#7317)
- Allow for using more than one spam checker module at once. (#7435)
- Add additional authentication checks for
m.room.power_levels
event per MSC2209. (#7502) - Implement room version 6 per MSC2240. (#7506)
- Add highly experimental option to move event persistence off master. (#7281, #7374, #7436, #7440, #7475, #7490, #7491, #7492, #7493, #7495, #7515, #7516, #7517, #7542)
Bugfixes
- Fix a bug where event updates might not be sent over replication to worker processes after the stream falls behind. (#7384)
- Allow expired user accounts to log out their device sessions. (#7443)
- Fix a bug that would cause Synapse not to resync out-of-sync device lists. (#7453)
- Prevent rooms with 0 members or with invalid version strings from breaking group queries. (#7465)
- Workaround for an upstream Twisted bug that caused Synapse to become unresponsive after startup. (#7473)
- Fix Redis reconnection logic that can result in missed updates over replication if master reconnects to Redis without restarting. (#7482)
- When sending
m.room.member
events, omitdisplayname
andavatar_url
if they aren't set instead of setting them tonull
. Contributed by Aaron Raimist. (#7497) - Fix incorrect
method
label onsynapse_http_matrixfederationclient_{requests,responses}
prometheus metrics. (#7503) - Ignore incoming presence events from other homeservers if presence is disabled locally. (#7508)
- Fix a long-standing bug that broke the update remote profile background process. (#7511)
- Hash passwords as early as possible during password reset. (#7538)
- Fix bug where a local user leaving a room could fail under rare circumstances. (#7548)
- Fix "Missing RelayState parameter" error when using user interactive authentication with SAML for some SAML providers. (#7552)
- Fix exception
'GenericWorkerReplicationHandler' object has no attribute 'send_federation_ack'
, introduced in v1.13.0. (#7564) synctl
now warns if it was unable to stop Synapse and will not attempt to start Synapse if nothing was stopped. Contributed by Romain Bouyé. (#6598)
Updates to the Docker image
- Update docker runtime image to Alpine v3.11. Contributed by @Starbix. (#7398)
Improved Documentation
- Update information about mapping providers for SAML and OpenID. (#7458)
- Add additional reverse proxy example for Caddy v2. Contributed by Jeff Peeler. (#7463)
- Fix copy-paste error in
ServerNoticesConfig
docstring. Contributed by @ptman. (#7477) - Improve the formatting of
reverse_proxy.md
. (#7514) - Change the systemd worker service to check that the worker config file exists instead of silently failing. Contributed by David Vo. (#7528)
- Minor clarifications to the TURN docs. (#7533)
Internal Changes
- Add typing annotations in
synapse.federation
. (#7382) - Convert the room handler to async/await. (#7396)
- Improve performance of
get_e2e_cross_signing_key
. (#7428) - Improve performance of
mark_as_sent_devices_by_remote
. (#7429, #7562) - Add type hints to the SAML handler. (#7445)
- Remove storage method
get_hosts_in_room
that is no longer called anywhere. (#7448) - Fix some typos in the
notice_expiry
templates. (#7449) - Convert the federation handler to async/await. (#7459)
- Convert the search handler to async/await. (#7460)
- Add type hints to
synapse.event_auth
. (#7505) - Convert the room member handler to async/await. (#7507)
- Add type hints to room member handler. (#7513)
- Fix typing annotations in
tests.replication
. (#7518) - Remove some redundant Python 2 support code. (#7519)
- All endpoints now respond with a 200 OK for
OPTIONS
requests. (#7534, #7560) - Synapse now exports detailed allocator statistics and basic GC timings as Prometheus metrics (
pypy_gc_time_seconds_total
andpypy_memory_bytes
) when run under PyPy. Contributed by Ivan Shapovalov. (#7536) - Remove Ubuntu Cosmic and Disco from the list of distributions which we provide
.deb
s for, due to end-of-life. (#7539) - Make worker processes return a stubbed-out response to
GET /presence
requests. (#7545) - Optimise some references to
hs.config
. (#7546) - On upgrade room only send canonical alias once. (#7547)
- Fix some indentation inconsistencies in the sample config. (#7550)
- Include
synapse.http.site
in type checking. (#7553) - Fix some test code to not mangle stacktraces, to make it easier to debug errors. (#7554)
- Refresh apt cache when building
dh_virtualenv
docker image. (#7555) - Stop logging some expected HTTP request errors as exceptions. (#7556, #7563)
- Convert sending mail to async/await. (#7557)
- Simplify
reap_monthly_active_users
. (#7558)
Synapse 1.13.0 (2020-05-19)
This release brings some potential changes necessary for certain configurations of Synapse:
- If your Synapse is configured to use SSO and have a custom
sso_redirect_confirm_template_dir
configuration option set, you will need to duplicate the newsso_auth_confirm.html
,sso_auth_success.html
andsso_account_deactivated.html
templates into that directory. - Synapse plugins using the
complete_sso_login
method ofsynapse.module_api.ModuleApi
should instead switch to the async/await version,complete_sso_login_async
, which includes additional checks. The former version is now deprecated. - A bug was introduced in Synapse 1.4.0 which could cause the room directory to be incomplete or empty if Synapse was upgraded directly from v1.2.1 or earlier, to versions between v1.4.0 and v1.12.x.
Please review the upgrade notes for more details on these changes and for general upgrade guidance.
Notice of change to the default git
branch for Synapse
With the release of Synapse 1.13.0, the default git
branch for Synapse has
changed to develop
, which is the development tip. This is more consistent with
common practice and modern git
usage.
The master
branch, which tracks the latest release, is still available. It is
recommended that developers and distributors who have scripts which run builds
using the default branch of Synapse should therefore consider pinning their
scripts to master
.
Internal Changes
- Update the version of dh-virtualenv we use to build debs, and add focal to the list of target distributions. (#7526)
Synapse 1.13.0rc3 (2020-05-18)
Bugfixes
- Hash passwords as early as possible during registration. (#7523)
Synapse 1.13.0rc2 (2020-05-14)
Bugfixes
- Fix a long-standing bug which could cause messages not to be sent over federation, when state events with state keys matching user IDs (such as custom user statuses) were received. (#7376)
- Restore compatibility with non-compliant clients during the user interactive authentication process, fixing a problem introduced in v1.13.0rc1. (#7483)
Internal Changes
- Fix linting errors in new version of Flake8. (#7470)
Synapse 1.13.0rc1 (2020-05-11)
Features
- Extend the
web_client_location
option to accept an absolute URL to use as a redirect. Adds a warning when running the web client on the same hostname as homeserver. Contributed by Martin Milata. (#7006) - Set
Referrer-Policy
header tono-referrer
on media downloads. (#7009) - Add support for running replication over Redis when using workers. (#7040, #7325, #7352, #7401, #7427, #7439, #7446, #7450, #7454)
- Admin API
POST /_synapse/admin/v1/join/<roomIdOrAlias>
to join users to a room likeauto_join_rooms
for creation of users. (#7051) - Add options to prevent users from changing their profile or associated 3PIDs. (#7096)
- Support SSO in the user interactive authentication workflow. (#7102, #7186, #7279, #7343)
- Allow server admins to define and enforce a password policy (MSC2000). (#7118)
- Improve the support for SSO authentication on the login fallback page. (#7152, #7235)
- Always whitelist the login fallback in the SSO configuration if
public_baseurl
is set. (#7153) - Admin users are no longer required to be in a room to create an alias for it. (#7191)
- Require admin privileges to enable room encryption by default. This does not affect existing rooms. (#7230)
- Add a config option for specifying the value of the Accept-Language HTTP header when generating URL previews. (#7265)
- Allow
/requestToken
endpoints to hide the existence (or lack thereof) of 3PID associations on the homeserver. (#7315) - Add a configuration setting to tweak the threshold for dummy events. (#7422)
Bugfixes
- Don't attempt to use an invalid sqlite config if no database configuration is provided. Contributed by @nekatak. (#6573)
- Fix single-sign on with CAS systems: pass the same service URL when requesting the CAS ticket and when calling the
proxyValidate
URL. Contributed by @Naugrimm. (#6634) - Fix missing field
default
when fetching user-defined push rules. (#6639) - Improve error responses when accessing remote public room lists. (#6899, #7368)
- Transfer alias mappings on room upgrade. (#6946)
- Ensure that a user interactive authentication session is tied to a single request. (#7068, #7455)
- Fix a bug in the federation API which could cause occasional "Failed to get PDU" errors. (#7089)
- Return the proper error (
M_BAD_ALIAS
) when a non-existant canonical alias is provided. (#7109) - Fix a bug which meant that groups updates were not correctly replicated between workers. (#7117)
- Fix starting workers when federation sending not split out. (#7133)
- Ensure
is_verified
is a boolean in responses toGET /_matrix/client/r0/room_keys/keys
. Also warn the user if they forgot theversion
query param. (#7150) - Fix error page being shown when a custom SAML handler attempted to redirect when processing an auth response. (#7151)
- Avoid importing
sqlite3
when using the postgres backend. Contributed by David Vo. (#7155) - Fix excessive CPU usage by
prune_old_outbound_device_pokes
job. (#7159) - Fix a bug which could cause outbound federation traffic to stop working if a client uploaded an incorrect e2e device signature. (#7177)
- Fix a bug which could cause incorrect 'cyclic dependency' error. (#7178)
- Fix a bug that could cause a user to be invited to a server notices (aka System Alerts) room without any notice being sent. (#7199)
- Fix some worker-mode replication handling not being correctly recorded in CPU usage stats. (#7203)
- Do not allow a deactivated user to login via SSO. (#7240, #7259)
- Fix --help command-line argument. (#7249)
- Fix room publish permissions not being checked on room creation. (#7260)
- Reject unknown session IDs during user interactive authentication instead of silently creating a new session. (#7268)
- Fix a SQL query introduced in Synapse 1.12.0 which could cause large amounts of logging to the postgres slow-query log. (#7274)
- Persist user interactive authentication sessions across workers and Synapse restarts. (#7302)
- Fixed backwards compatibility logic of the first value of
trusted_third_party_id_servers
being used foraccount_threepid_delegates.email
, which occurs when the former, deprecated option is set and the latter is not. (#7316) - Fix a bug where event updates might not be sent over replication to worker processes after the stream falls behind. (#7337, #7358)
- Fix bad error handling that would cause Synapse to crash if it's provided with a YAML configuration file that's either empty or doesn't parse into a key-value map. (#7341)
- Fix incorrect metrics reporting for
renew_attestations
background task. (#7344) - Prevent non-federating rooms from appearing in responses to federated
POST /publicRoom
requests when a filter was included. (#7367) - Fix a bug which would cause the room durectory to be incorrectly populated if Synapse was upgraded directly from v1.2.1 or earlier to v1.4.0 or later. Note that this fix does not apply retrospectively; see the upgrade notes for more information. (#7387)
- Fix bug in
EventContext.deserialize
. (#7393)
Improved Documentation
- Update Debian installation instructions to recommend installing the
virtualenv
package instead ofpython3-virtualenv
. (#6892) - Improve the documentation for database configuration. (#6988)
- Improve the documentation of application service configuration files. (#7091)
- Update pre-built package name for FreeBSD. (#7107)
- Update postgres docs with login troubleshooting information. (#7119)
- Clean up INSTALL.md a bit. (#7141)
- Add documentation for running a local CAS server for testing. (#7147)
- Improve README.md by being explicit about public IP recommendation for TURN relaying. (#7167)
- Fix a small typo in the
metrics_flags
config option. (#7171) - Update the contributed documentation on managing synapse workers with systemd, and bring it into the core distribution. (#7234)
- Add documentation to the
password_providers
config option. Add known password provider implementations to docs. (#7238, #7248) - Modify suggested nginx reverse proxy configuration to match Synapse's default file upload size. Contributed by @ProCycleDev. (#7251)
- Documentation of media_storage_providers options updated to avoid misunderstandings. Contributed by Tristan Lins. (#7272)
- Add documentation on monitoring workers with Prometheus. (#7357)
- Clarify endpoint usage in the users admin api documentation. (#7361)
Deprecations and Removals
- Remove nonfunctional
captcha_bypass_secret
option fromhomeserver.yaml
. (#7137)
Internal Changes
- Add benchmarks for LruCache. (#6446)
- Return total number of users and profile attributes in admin users endpoint. Contributed by Awesome Technologies Innovationslabor GmbH. (#6881)
- Change device list streams to have one row per ID. (#7010)
- Remove concept of a non-limited stream. (#7011)
- Move catchup of replication streams logic to worker. (#7024, #7195, #7226, #7239, #7286, #7290, #7318, #7326, #7378, #7421)
- Convert some of synapse.rest.media to async/await. (#7110, #7184, #7241)
- De-duplicate / remove unused REST code for login and auth. (#7115)
- Convert
*StreamRow
classes to inner classes. (#7116) - Clean up some LoggingContext code. (#7120, #7181, #7183, #7408, #7426)
- Add explicit
instance_id
for USER_SYNC commands and remove implicitconn_id
usage. (#7128) - Refactored the CAS authentication logic to a separate class. (#7136)
- Run replication streamers on workers. (#7146)
- Add tests for outbound device pokes. (#7157)
- Fix device list update stream ids going backward. (#7158)
- Use
stream.current_token()
and removestream_positions()
. (#7172) - Move client command handling out of TCP protocol. (#7185)
- Move server command handling out of TCP protocol. (#7187)
- Fix consistency of HTTP status codes reported in log lines. (#7188)
- Only run one background database update at a time. (#7190)
- Remove sent outbound device list pokes from the database. (#7192)
- Add a background database update job to clear out duplicate
device_lists_outbound_pokes
. (#7193) - Remove some extraneous debugging log lines. (#7207)
- Add explicit Python build tooling as dependencies for the snapcraft build. (#7213)
- Add typing information to federation server code. (#7219)
- Extend room admin api (
GET /_synapse/admin/v1/rooms
) with additional attributes. (#7225) - Unblacklist '/upgrade creates a new room' sytest for workers. (#7228)
- Remove redundant checks on
daemonize
from synctl. (#7233) - Upgrade jQuery to v3.4.1 on fallback login/registration pages. (#7236)
- Change log line that told user to implement onLogin/onRegister fallback js functions to a warning, instead of an info, so it's more visible. (#7237)
- Correct the parameters of a test fixture. Contributed by Isaiah Singletary. (#7243)
- Convert auth handler to async/await. (#7261)
- Add some unit tests for replication. (#7278)
- Improve typing annotations in
synapse.replication.tcp.streams.Stream
. (#7291) - Reduce log verbosity of url cache cleanup tasks. (#7295)
- Fix sample SAML Service Provider configuration. Contributed by @frcl. (#7300)
- Fix StreamChangeCache to work with multiple entities changing on the same stream id. (#7303)
- Fix an incorrect import in IdentityHandler. (#7319)
- Reduce logging verbosity for successful federation requests. (#7321)
- Convert some federation handler code to async/await. (#7338)
- Fix collation for postgres for unit tests. (#7359)
- Convert RegistrationWorkerStore.is_server_admin and dependent code to async/await. (#7363)
- Add an
instance_name
toRDATA
andPOSITION
replication commands. (#7364) - Thread through instance name to replication client. (#7369)
- Convert synapse.server_notices to async/await. (#7394)
- Convert synapse.notifier to async/await. (#7395)
- Fix issues with the Python package manifest. (#7404)
- Prevent methods in
synapse.handlers.auth
from polling the homeserver config every request. (#7420) - Speed up fetching device lists changes when handling
/sync
requests. (#7423) - Run group attestation renewal in series rather than parallel for performance. (#7442)
Synapse 1.12.4 (2020-04-23)
No significant changes.
Synapse 1.12.4rc1 (2020-04-22)
Features
- Always send users their own device updates. (#7160)
- Add support for handling GET requests for
account_data
on a worker. (#7311)
Bugfixes
- Fix a bug that prevented cross-signing with users on worker-mode synapses. (#7255)
- Do not treat display names as globs in push rules. (#7271)
- Fix a bug with cross-signing devices belonging to remote users who did not share a room with any user on the local homeserver. (#7289)
Synapse 1.12.3 (2020-04-03)
- Remove the the pin to Pillow 7.0 which was introduced in Synapse 1.12.2, and correctly fix the issue with building the Debian packages. (#7212)
Synapse 1.12.2 (2020-04-02)
This release works around an issue with building the debian packages.
No other significant changes since 1.12.1.
Synapse 1.12.1 (2020-04-02)
No significant changes since 1.12.1rc1.
Synapse 1.12.1rc1 (2020-03-31)
Bugfixes
- Fix starting workers when federation sending not split out. (#7133). Introduced in v1.12.0.
- Avoid importing
sqlite3
when using the postgres backend. Contributed by David Vo. (#7155). Introduced in v1.12.0rc1. - Fix a bug which could cause outbound federation traffic to stop working if a client uploaded an incorrect e2e device signature. (#7177). Introduced in v1.11.0.
Synapse 1.12.0 (2020-03-23)
Debian packages and Docker images are rebuilt using the latest versions of dependency libraries, including Twisted 20.3.0. Please see security advisory below.
Potential slow database update during upgrade
Synapse 1.12.0 includes a database update which is run as part of the upgrade, and which may take some time (several hours in the case of a large server). Synapse will not respond to HTTP requests while this update is taking place. For imformation on seeing if you are affected, and workaround if you are, see the upgrade notes.
Security advisory
Synapse may be vulnerable to request-smuggling attacks when it is used with a reverse-proxy. The vulnerabilties are fixed in Twisted 20.3.0, and are described in CVE-2020-10108 and CVE-2020-10109. For a good introduction to this class of request-smuggling attacks, see https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn.
We are not aware of these vulnerabilities being exploited in the wild, and do not believe that they are exploitable with current versions of any reverse proxies. Nevertheless, we recommend that all Synapse administrators ensure that they have the latest versions of the Twisted library to ensure that their installation remains secure.
- Administrators using the
matrix.org
Docker image or the Debian/Ubuntu packages frommatrix.org
should ensure that they have version 1.12.0 installed: these images include Twisted 20.3.0. - Administrators who have installed Synapse from
source
should upgrade Twisted within their virtualenv by running:
<path_to_virtualenv>/bin/pip install 'Twisted>=20.3.0'
- Administrators who have installed Synapse from distribution packages should consult the information from their distributions.
The matrix.org
Synapse instance was not vulnerable to these vulnerabilities.
Advance notice of change to the default git
branch for Synapse
Currently, the default git
branch for Synapse is master
, which tracks the
latest release.
After the release of Synapse 1.13.0, we intend to change this default to
develop
, which is the development tip. This is more consistent with common
practice and modern git
usage.
Although we try to keep develop
in a stable state, there may be occasions
where regressions creep in. Developers and distributors who have scripts which
run builds using the default branch of Synapse
should therefore consider
pinning their scripts to master
.
Synapse 1.12.0rc1 (2020-03-19)
Features
- Changes related to room alias management (MSC2432):
- Publishing/removing a room from the room directory now requires the user to have a power level capable of modifying the canonical alias, instead of the room aliases. (#6965)
- Validate the
alt_aliases
property of canonical alias events. (#6971) - Users with a power level sufficient to modify the canonical alias of a room can now delete room aliases. (#6986)
- Implement updated authorization rules and redaction rules for aliases events, from MSC2261 and MSC2432. (#7037)
- Stop sending m.room.aliases events during room creation and upgrade. (#6941)
- Synapse no longer uses room alias events to calculate room names for push notifications. (#6966)
- The room list endpoint no longer returns a list of aliases. (#6970)
- Remove special handling of aliases events from MSC2260 added in v1.10.0rc1. (#7034)
- Expose the
synctl
,hash_password
andgenerate_config
commands in the snapcraft package. Contributed by @devec0. (#6315) - Check that server_name is correctly set before running database updates. (#6982)
- Break down monthly active users by
appservice_id
and emit via Prometheus. (#7030) - Render a configurable and comprehensible error page if something goes wrong during the SAML2 authentication process. (#7058, #7067)
- Add an optional parameter to control whether other sessions are logged out when a user's password is modified. (#7085)
- Add prometheus metrics for the number of active pushers. (#7103, #7106)
- Improve performance when making HTTPS requests to sygnal, sydent, etc, by sharing the SSL context object between connections. (#7094)
Bugfixes
- When a user's profile is updated via the admin API, also generate a displayname/avatar update for that user in each room. (#6572)
- Fix a couple of bugs in email configuration handling. (#6962)
- Fix an issue affecting worker-based deployments where replication would stop working, necessitating a full restart, after joining a large room. (#6967)
- Fix
duplicate key
error which was logged when rejoining a room over federation. (#6968) - Prevent user from setting 'deactivated' to anything other than a bool on the v2 PUT /users Admin API. (#6990)
- Fix py35-old CI by using native tox package. (#7018)
- Fix a bug causing
org.matrix.dummy_event
to be included in responses from/sync
. (#7035) - Fix a bug that renders UTF-8 text files incorrectly when loaded from media. Contributed by @TheStranjer. (#7044)
- Fix a bug that would cause Synapse to respond with an error about event visibility if a client tried to request the state of a room at a given token. (#7066)
- Repair a data-corruption issue which was introduced in Synapse 1.10, and fixed in Synapse 1.11, and which could cause
/sync
to return with 404 errors about missing events and unknown rooms. (#7070) - Fix a bug causing account validity renewal emails to be sent even if the feature is turned off in some cases. (#7074)
Improved Documentation
- Updated CentOS8 install instructions. Contributed by Richard Kellner. (#6925)
- Fix
POSTGRES_INITDB_ARGS
in thecontrib/docker/docker-compose.yml
example docker-compose configuration. (#6984) - Change date in INSTALL.md for last date of getting TLS certificates to November 2019. (#7015)
- Document that the fallback auth endpoints must be routed to the same worker node as the register endpoints. (#7048)
Deprecations and Removals
Internal Changes
- Add type hints to
logging/context.py
. (#6309) - Add some clarifications to
README.md
in the database schema directory. (#6615) - Refactoring work in preparation for changing the event redaction algorithm. (#6874, #6875, #6983, #7003)
- Improve performance of v2 state resolution for large rooms. (#6952, #7095)
- Reduce time spent doing GC, by freezing objects on startup. (#6953)
- Minor perfermance fixes to
get_auth_chain_ids
. (#6954) - Don't record remote cross-signing keys in the
devices
table. (#6956) - Use flake8-comprehensions to enforce good hygiene of list/set/dict comprehensions. (#6957)
- Merge worker apps together. (#6964, #7002, #7055, #7104)
- Remove redundant
store_room
call fromFederationHandler._process_received_pdu
. (#6979) - Update warning for incorrect database collation/ctype to include link to documentation. (#6985)
- Add some type annotations to the database storage classes. (#6987)
- Port
synapse.handlers.presence
to async/await. (#6991, #7019) - Add some type annotations to the federation base & client classes. (#6995)
- Port
synapse.rest.keys
to async/await. (#7020) - Add a type check to
is_verified
when processing room keys. (#7045) - Add type annotations and comments to the auth handler. (#7063)
Synapse 1.11.1 (2020-03-03)
This release includes a security fix impacting installations using Single Sign-On (i.e. SAML2 or CAS) for authentication. Administrators of such installations are encouraged to upgrade as soon as possible.
The release also includes fixes for a couple of other bugs.
Bugfixes
- Add a confirmation step to the SSO login flow before redirecting users to the redirect URL. (b2bd54a2, 65c73cdf, a0178df1)
- Fixed set a user as an admin with the admin API
PUT /_synapse/admin/v2/users/<user_id>
. Contributed by @dklimpel. (#6910) - Fix bug introduced in Synapse 1.11.0 which sometimes caused errors when joining rooms over federation, with
'coroutine' object has no attribute 'event_id'
. (#6996)
Synapse 1.11.0 (2020-02-21)
Improved Documentation
- Small grammatical fixes to the ACME v1 deprecation notice. (#6944)
Synapse 1.11.0rc1 (2020-02-19)
Features
- Admin API to add or modify threepids of user accounts. (#6769)
- Limit the number of events that can be requested by the backfill federation API to 100. (#6864)
- Add ability to run some group APIs on workers. (#6866)
- Reject device display names over 100 characters in length to prevent abuse. (#6882)
- Add ability to route federation user device queries to workers. (#6873)
- The result of a user directory search can now be filtered via the spam checker. (#6888)
- Implement new
GET /_matrix/client/unstable/org.matrix.msc2432/rooms/{roomId}/aliases
endpoint as per MSC2432. (#6939, #6948, #6949) - Stop sending
m.room.alias
events wheng adding / removing aliases. Checkalt_aliases
in the latestm.room.canonical_alias
event when deleting an alias. (#6904) - Change the default power levels of invites, tombstones and server ACLs for new rooms. (#6834)
Bugfixes
- Fixed third party event rules function
on_create_room
's return value being ignored. (#6781) - Allow URL-encoded User IDs on
/_synapse/admin/v2/users/<user_id>[/admin]
endpoints. Thanks to @NHAS for reporting. (#6825) - Fix Synapse refusing to start if
federation_certificate_verification_whitelist
option is blank. (#6849) - Fix errors from logging in the purge jobs related to the message retention policies support. (#6945)
- Return a 404 instead of 200 for querying information of a non-existant user through the admin API. (#6901)
Updates to the Docker image
- The deprecated "generate-config-on-the-fly" mode is no longer supported. (#6918)
Improved Documentation
- Add details of PR merge strategy to contributing docs. (#6846)
- Spell out that the last event sent to a room won't be deleted by a purge. (#6891)
- Update Synapse's documentation to warn about the deprecation of ACME v1. (#6905, #6907, #6909)
- Add documentation for the spam checker. (#6906)
- Fix worker docs to point
/publicised_groups
API correctly. (#6938) - Clean up and update docs on setting up federation. (#6940)
- Add a warning about indentation to generated configuration files. (#6920)
- Databases created using the compose file in contrib/docker will now always have correct encoding and locale settings. Contributed by Fridtjof Mund. (#6921)
- Update pip install directions in readme to avoid error when using zsh. (#6855)
Deprecations and Removals
- Remove
m.lazy_load_members
fromunstable_features
since lazy loading is in the stable Client-Server API version r0.5.0. (#6877)
Internal Changes
- Add type hints to
SyncHandler
. (#6821) - Refactoring work in preparation for changing the event redaction algorithm. (#6823, #6827, #6854, #6856, #6857, #6858)
- Fix stacktraces when using
ObservableDeferred
and async/await. (#6836) - Port much of
synapse.handlers.federation
to async/await. (#6837, #6840) - Populate
rooms.room_version
database column at startup, rather than in a background update. (#6847) - Reduce amount we log at
INFO
level. (#6833, #6862) - Remove unused
get_room_stats_state
method. (#6869) - Add typing to
synapse.federation.sender
and port to async/await. (#6871) - Refactor
_EventInternalMetadata
object to improve type safety. (#6872) - Add an additional entry to the SyTest blacklist for worker mode. (#6883)
- Fix the use of sed in the linting scripts when using BSD sed. (#6887)
- Add type hints to the spam checker module. (#6915)
- Convert the directory handler tests to use HomeserverTestCase. (#6919)
- Increase DB/CPU perf of
_is_server_still_joined
check. (#6936) - Tiny optimisation for incoming HTTP request dispatch. (#6950)
Synapse 1.10.1 (2020-02-17)
Bugfixes
- Fix a bug introduced in Synapse 1.10.0 which would cause room state to be cleared in the database if Synapse was upgraded direct from 1.2.1 or earlier to 1.10.0. (#6924)
Synapse 1.10.0 (2020-02-12)
WARNING to client developers: As of this release Synapse validates client_secret
parameters in the Client-Server API as per the spec. See #6766 for details.
Updates to the Docker image
- Update the docker images to Alpine Linux 3.11. (#6897)
Synapse 1.10.0rc5 (2020-02-11)
Bugfixes
- Fix the filtering introduced in 1.10.0rc3 to also apply to the state blocks returned by
/sync
. (#6884)
Synapse 1.10.0rc4 (2020-02-11)
This release candidate was built incorrectly and is superceded by 1.10.0rc5.
Synapse 1.10.0rc3 (2020-02-10)
Features
- Filter out
m.room.aliases
from the CS API to mitigate abuse while a better solution is specced. (#6878)
Internal Changes
- Fix continuous integration failures with old versions of
pip
, which were introduced by a release of thezipp
library. (#6880)
Synapse 1.10.0rc2 (2020-02-06)
Bugfixes
- Fix an issue with cross-signing where device signatures were not sent to remote servers. (#6844)
- Fix to the unknown remote device detection which was introduced in 1.10.rc1. (#6848)
Internal Changes
- Detect unexpected sender keys on remote encrypted events and resync device lists. (#6850)
Synapse 1.10.0rc1 (2020-01-31)
Features
- Add experimental support for updated authorization rules for aliases events, from MSC2260. (#6787, #6790, #6794)
Bugfixes
- Warn if postgres database has a non-C locale, as that can cause issues when upgrading locales (e.g. due to upgrading OS). (#6734)
- Minor fixes to
PUT /_synapse/admin/v2/users
admin api. (#6761) - Validate
client_secret
parameter using the regex provided by the Client-Server API, temporarily allowing:
characters for older clients. The:
character will be removed in a future release. (#6767) - Fix persisting redaction events that have been redacted (or otherwise don't have a redacts key). (#6771)
- Fix outbound federation request metrics. (#6795)
- Fix bug where querying a remote user's device keys that weren't cached resulted in only returning a single device. (#6796)
- Fix race in federation sender worker that delayed sending of device updates. (#6799, #6800)
- Fix bug where Synapse didn't invalidate cache of remote users' devices when Synapse left a room. (#6801)
- Fix waking up other workers when remote server is detected to have come back online. (#6811)
Improved Documentation
- Clarify documentation related to
user_dir
andfederation_reader
workers. (#6775)
Internal Changes
- Record room versions in the
rooms
table. (#6729, #6788, #6810) - Propagate cache invalidates from workers to other workers. (#6748)
- Remove some unnecessary admin handler abstraction methods. (#6751)
- Add some debugging for media storage providers. (#6757)
- Detect unknown remote devices and mark cache as stale. (#6776, #6819)
- Attempt to resync remote users' devices when detected as stale. (#6786)
- Delete current state from the database when server leaves a room. (#6792)
- When a client asks for a remote user's device keys check if the local cache for that user has been marked as potentially stale. (#6797)
- Add background update to clean out left rooms from current state. (#6802, #6816)
- Refactoring work in preparation for changing the event redaction algorithm. (#6803, #6805, #6806, #6807, #6820)
Synapse 1.9.1 (2020-01-28)
Bugfixes
- Fix bug where setting
mau_limit_reserved_threepids
config would cause Synapse to refuse to start. (#6793)
Synapse 1.9.0 (2020-01-23)
WARNING: As of this release, Synapse no longer supports versions of SQLite before 3.11, and will refuse to start when configured to use an older version. Administrators are recommended to migrate their database to Postgres (see instructions here).
If your Synapse deployment uses workers, note that the reverse-proxy configurations for the synapse.app.media_repository
, synapse.app.federation_reader
and synapse.app.event_creator
workers have changed, with the addition of a few paths (see the updated configurations here). Existing configurations will continue to work.
Improved Documentation
- Fix endpoint documentation for the List Rooms admin API. (#6770)
Synapse 1.9.0rc1 (2020-01-22)
Features
- Allow admin to create or modify a user. Contributed by Awesome Technologies Innovationslabor GmbH. (#5742)
- Add new quarantine media admin APIs to quarantine by media ID or by user who uploaded the media. (#6681, #6756)
- Add
org.matrix.e2e_cross_signing
tounstable_features
in/versions
as per MSC1756. (#6712) - Add a new admin API to list and filter rooms on the server. (#6720)
Bugfixes
- Correctly proxy HTTP errors due to API calls to remote group servers. (#6654)
- Fix media repo admin APIs when using a media worker. (#6664)
- Fix "CRITICAL" errors being logged when a request is received for a uri containing non-ascii characters. (#6682)
- Fix a bug where we would assign a numeric user ID if somebody tried registering with an empty username. (#6690)
- Fix
purge_room
admin API. (#6711) - Fix a bug causing Synapse to not always purge quiet rooms with a low
max_lifetime
in their message retention policies when running the automated purge jobs. (#6714) - Fix the
synapse_port_db
not correctly running background updates. Thanks @tadzik for reporting. (#6718) - Fix changing password via user admin API. (#6730)
- Fix
/events/:event_id
deprecated API. (#6731) - Fix monthly active user limiting support for worker mode, fixes #4639. (#6742)
- Fix bug when setting
account_validity
to an empty block in the config. Thanks to @Sorunome for reporting. (#6747) - Fix
AttributeError: 'NoneType' object has no attribute 'get'
inhash_password
when configuration has an emptypassword_config
. Contributed by @ivilata. (#6753) - Fix the
docker-compose.yaml
overriding the entire/etc
folder of the container. Contributed by Fabian Meyer. (#6656)
Improved Documentation
- Fix a typo in the configuration example for purge jobs in the sample configuration file. (#6621)
- Add complete documentation of the message retention policies support. (#6624, #6665)
- Add some helpful tips about changelog entries to the GitHub pull request template. (#6663)
- Clarify the
account_validity
andemail
sections of the sample configuration. (#6685) - Add more endpoints to the documentation for Synapse workers. (#6698)
Deprecations and Removals
- Synapse no longer supports versions of SQLite before 3.11, and will refuse to start when configured to use an older version. Administrators are recommended to migrate their database to Postgres (see instructions here). (#6675)
Internal Changes
- Add
local_current_membership
table for tracking local user membership state in rooms. (#6655, #6728) - Port
synapse.replication.tcp
to async/await. (#6666) - Fixup
synapse.replication
to pass mypy checks. (#6667) - Allow
additional_resources
to implementIResource
directly. (#6686) - Allow REST endpoint implementations to raise a
RedirectException
, which will redirect the user's browser to a given location. (#6687) - Updates and extensions to the module API. (#6688)
- Updates to the SAML mapping provider API. (#6689, #6723)
- Remove redundant
RegistrationError
class. (#6691) - Don't block processing of incoming EDUs behind processing PDUs in the same transaction. (#6697)
- Remove duplicate check for the
session
query parameter on the/auth/xxx/fallback/web
Client-Server endpoint. (#6702) - Attempt to retry sending a transaction when we detect a remote server has come back online, rather than waiting for a transaction to be triggered by new data. (#6706)
- Add
StateMap
type alias to simplify types. (#6715) - Add a
DeltaState
to track changes to be made to current state during event persistence. (#6716) - Add more logging around message retention policies support. (#6717)
- When processing a SAML response, log the assertions for easier configuration. (#6724)
- Fixup
synapse.rest
to pass mypy. (#6732, #6764) - Fixup
synapse.api
to pass mypy. (#6733) - Allow streaming cache 'invalidate all' to workers. (#6749)
- Remove unused CI docker compose files. (#6754)
Synapse 1.8.0 (2020-01-09)
WARNING: As of this release Synapse will refuse to start if the log_file
config option is specified. Support for the option was removed in v1.3.0.
Bugfixes
- Fix
GET
request on/_synapse/admin/v2/users
endpoint. Contributed by Awesome Technologies Innovationslabor GmbH. (#6563) - Fix incorrect signing of responses from the key server implementation. (#6657)
Synapse 1.8.0rc1 (2020-01-07)
Features
- Add v2 APIs for the
send_join
andsend_leave
federation endpoints (as described in MSC1802). (#6349) - Add a develop script to generate full SQL schemas. (#6394)
- Add custom SAML username mapping functionality through an external provider plugin. (#6411)
- Automatically delete empty groups/communities. (#6453)
- Add option
limit_profile_requests_to_users_who_share_rooms
to prevent requirement of a local user sharing a room with another user to query their profile information. (#6523) - Add an
export_signing_key
script to extract the public part of signing keys when rotating them. (#6546) - Add experimental config option to specify multiple databases. (#6580)
- Raise an error if someone tries to use the
log_file
config option. (#6626)
Bugfixes
- Prevent redacted events from being returned during message search. (#6377, #6522)
- Prevent error on trying to search a upgraded room when the server is not in the predecessor room. (#6385)
- Improve performance of looking up cross-signing keys. (#6486)
- Fix race which occasionally caused deleted devices to reappear. (#6514)
- Fix missing row in
device_max_stream_id
that could cause unable to decrypt errors after server restart. (#6555) - Fix a bug which meant that we did not send systemd notifications on startup if acme was enabled. (#6571)
- Fix exception when fetching the
matrix.org:ed25519:auto
key. (#6625) - Fix bug where a moderator upgraded a room and became an admin in the new room. (#6633)
- Fix an error which was thrown by the
PresenceHandler
_on_shutdown
handler. (#6640) - Fix exceptions in the synchrotron worker log when events are rejected. (#6645)
- Ensure that upgraded rooms are removed from the directory. (#6648)
- Fix a bug causing Synapse not to fetch missing events when it believes it has every event in the room. (#6652)
Improved Documentation
- Document the Room Shutdown Admin API. (#6541)
- Reword sections of docs/federate.md that explained delegation at time of Synapse 1.0 transition. (#6601)
- Added the section 'Configuration' in docs/turn-howto.md. (#6614)
Deprecations and Removals
- Remove redundant code from event authorisation implementation. (#6502)
- Remove unused, undocumented
/_matrix/content
API. (#6628)
Internal Changes
- Add experimental support for multiple physical databases and split out state storage to separate data store. (#6245, #6510, #6511, #6513, #6564, #6565)
- Port sections of code base to async/await. (#6496, #6504, #6505, #6517, #6559, #6647, #6653)
- Remove
SnapshotCache
in favour ofResponseCache
. (#6506) - Silence mypy errors for files outside those specified. (#6512)
- Clean up some logging when handling incoming events over federation. (#6515)
- Test more folders against mypy. (#6534)
- Update
mypy
to new version. (#6537) - Adjust the sytest blacklist for worker mode. (#6538)
- Remove unused
get_pagination_rows
methods fromEventSource
classes. (#6557) - Clean up logs from the push notifier at startup. (#6558)
- Improve diagnostics on database upgrade failure. (#6570)
- Reduce the reconnect time when worker replication fails, to make it easier to catch up. (#6617)
- Simplify http handling by removing redundant
SynapseRequestFactory
. (#6619) - Add a workaround for synapse raising exceptions when fetching the notary's own key from the notary. (#6620)
- Automate generation of the sample log config. (#6627)
- Simplify event creation code by removing redundant queries on the
event_reference_hashes
table. (#6629) - Fix errors when
frozen_dicts
are enabled. (#6642)
Synapse 1.7.3 (2019-12-31)
This release fixes a long-standing bug in the state resolution algorithm.
Bugfixes
- Fix exceptions caused by state resolution choking on malformed events. (#6608)
Synapse 1.7.2 (2019-12-20)
This release fixes some regressions introduced in Synapse 1.7.0 and 1.7.1.
Bugfixes
- Fix a regression introduced in Synapse 1.7.1 which caused errors when attempting to backfill rooms over federation. (#6576)
- Fix a bug introduced in Synapse 1.7.0 which caused an error on startup when upgrading from versions before 1.3.0. (#6578)
Synapse 1.7.1 (2019-12-18)
This release includes several security fixes as well as a fix to a bug exposed by the security fixes. Administrators are encouraged to upgrade as soon as possible.
Security updates
- Fix a bug which could cause room events to be incorrectly authorized using events from a different room. (#6501, #6503, #6521, #6524, #6530, #6531)
- Fix a bug causing responses to the
/context
client endpoint to not use the pruned version of the event. (#6553) - Fix a cause of state resets in room versions 2 onwards. (#6556, #6560)
Bugfixes
- Fix a bug which could cause the federation server to incorrectly return errors when handling certain obscure event graphs. (#6526, #6527)
Synapse 1.7.0 (2019-12-13)
This release changes the default settings so that only local authenticated users can query the server's room directory. See the upgrade notes for details.
Support for SQLite versions before 3.11 is now deprecated. A future release will refuse to start if used with an SQLite version before 3.11.
Administrators are reminded that SQLite should not be used for production instances. Instructions for migrating to Postgres are available here. A future release of synapse will, by default, disable federation for servers using SQLite.
No significant changes since 1.7.0rc2.
Synapse 1.7.0rc2 (2019-12-11)
Bugfixes
- Fix incorrect error message for invalid requests when setting user's avatar URL. (#6497)
- Fix support for SQLite 3.7. (#6499)
- Fix regression where sending email push would not work when using a pusher worker. (#6507, #6509)
Synapse 1.7.0rc1 (2019-12-09)
Features
- Implement per-room message retention policies. (#5815, #6436)
- Add etag and count fields to key backup endpoints to help clients guess if there are new keys. (#5858)
- Add
/admin/v2/users
endpoint with pagination. Contributed by Awesome Technologies Innovationslabor GmbH. (#5925) - Require User-Interactive Authentication for
/account/3pid/add
, meaning the user's password will be required to add a third-party ID to their account. (#6119) - Implement the
/_matrix/federation/unstable/net.atleastfornow/state/<context>
API as drafted in MSC2314. (#6176) - Configure privacy-preserving settings by default for the room directory. (#6355)
- Add ephemeral messages support by partially implementing MSC2228. (#6409)
- Add support for MSC 2367, which allows specifying a reason on all membership events. (#6434)
Bugfixes
- Transfer non-standard power levels on room upgrade. (#6237)
- Fix error from the Pillow library when uploading RGBA images. (#6241)
- Correctly apply the event filter to the
state
,events_before
andevents_after
fields in the response to/context
requests. (#6329) - Fix caching devices for remote users when using workers, so that we don't attempt to refetch (and potentially fail) each time a user requests devices. (#6332)
- Prevent account data syncs getting lost across TCP replication. (#6333)
- Fix bug: TypeError in
register_user()
while using LDAP auth module. (#6406) - Fix an intermittent exception when handling read-receipts. (#6408)
- Fix broken guest registration when there are existing blocks of numeric user IDs. (#6420)
- Fix startup error when http proxy is defined. (#6421)
- Fix error when using synapse_port_db on a vanilla synapse db. (#6449)
- Fix uploading multiple cross signing signatures for the same user. (#6451)
- Fix bug which lead to exceptions being thrown in a loop when a cross-signed device is deleted. (#6462)
- Fix
synapse_port_db
not exiting with a 0 code if something went wrong during the port process. (#6470) - Improve sanity-checking when receiving events over federation. (#6472)
- Fix inaccurate per-block Prometheus metrics. (#6491)
- Fix small performance regression for sending invites. (#6493)
- Back out cross-signing code added in Synapse 1.5.0, which caused a performance regression. (#6494)
Improved Documentation
- Update documentation and variables in user contributed systemd reference file. (#6369, #6490)
- Fix link in the user directory documentation. (#6388)
- Add build instructions to the docker readme. (#6390)
- Switch Ubuntu package install recommendation to use python3 packages in INSTALL.md. (#6443)
- Write some docs for the quarantine_media api. (#6458)
- Convert CONTRIBUTING.rst to markdown (among other small fixes). (#6461)
Deprecations and Removals
- Remove admin/v1/users_paginate endpoint. Contributed by Awesome Technologies Innovationslabor GmbH. (#5925)
- Remove fallback for federation with old servers which lack the /federation/v1/state_ids API. (#6488)
Internal Changes
- Add benchmarks for structured logging and improve output performance. (#6266)
- Improve the performance of outputting structured logging. (#6322)
- Refactor some code in the event authentication path for clarity. (#6343, #6468, #6480)
- Clean up some unnecessary quotation marks around the codebase. (#6362)
- Complain on startup instead of 500'ing during runtime when
public_baseurl
isn't set when necessary. (#6379) - Add a test scenario to make sure room history purges don't break
/messages
in the future. (#6392) - Clarifications for the email configuration settings. (#6423)
- Add more tests to the blacklist when running in worker mode. (#6429)
- Refactor data store layer to support multiple databases in the future. (#6454, #6464, #6469, #6487)
- Port synapse.rest.client.v1 to async/await. (#6482)
- Port synapse.rest.client.v2_alpha to async/await. (#6483)
- Port SyncHandler to async/await. (#6484)
Synapse 1.6.1 (2019-11-28)
Security updates
This release includes a security fix (#6426, below). Administrators are encouraged to upgrade as soon as possible.
Bugfixes
- Clean up local threepids from user on account deactivation. (#6426)
- Fix startup error when http proxy is defined. (#6421)
Synapse 1.6.0 (2019-11-26)
Bugfixes
- Fix phone home stats reporting. (#6418)
Synapse 1.6.0rc2 (2019-11-25)
Bugfixes
- Fix a bug which could cause the background database update hander for event labels to get stuck in a loop raising exceptions. (#6407)
Synapse 1.6.0rc1 (2019-11-20)
Features
- Add federation support for cross-signing. (#5727)
- Increase default room version from 4 to 5, thereby enforcing server key validity period checks. (#6220)
- Add support for outbound http proxying via http_proxy/HTTPS_PROXY env vars. (#6238)
- Implement label-based filtering on
/sync
and/messages
(MSC2326). (#6301, #6310, #6340)
Bugfixes
- Fix LruCache callback deduplication for Python 3.8. Contributed by @V02460. (#6213)
- Remove a room from a server's public rooms list on room upgrade. (#6232, #6235)
- Delete keys from key backup when deleting backup versions. (#6253)
- Make notification of cross-signing signatures work with workers. (#6254)
- Fix exception when remote servers attempt to join a room that they're not allowed to join. (#6278)
- Prevent errors from appearing on Synapse startup if
git
is not installed. (#6284) - Appservice requests will no longer contain a double slash prefix when the appservice url provided ends in a slash. (#6306)
- Fix
/purge_room
admin API. (#6307) - Fix the
hidden
field in thedevices
table for SQLite versions prior to 3.23.0. (#6313) - Fix bug which casued rejected events to be persisted with the wrong room state. (#6320)
- Fix bug where
rc_login
ratelimiting would prematurely kick in. (#6335) - Prevent the server taking a long time to start up when guest registration is enabled. (#6338)
- Fix bug where upgrading a guest account to a full user would fail when account validity is enabled. (#6359)
- Fix
to_device
stream ID getting reset every time Synapse restarts, which had the potential to cause unable to decrypt errors. (#6363) - Fix permission denied error when trying to generate a config file with the docker image. (#6389)
Improved Documentation
- Contributor documentation now mentions script to run linters. (#6164)
- Modify CAPTCHA_SETUP.md to update the terms
private key
andpublic key
tosecret key
andsite key
respectively. Contributed by Yash Jipkate. (#6257) - Update
INSTALL.md
Email section to talk aboutaccount_threepid_delegates
. (#6272) - Fix a small typo in
account_threepid_delegates
configuration option. (#6273)
Internal Changes
- Add a CI job to test the
synapse_port_db
script. (#6140, #6276) - Convert EventContext to an attrs. (#6218)
- Move
persist_events
out from main data store. (#6240, #6300) - Reduce verbosity of user/room stats. (#6250)
- Reduce impact of debug logging. (#6251)
- Expose some homeserver functionality to spam checkers. (#6259)
- Change cache descriptors to always return deferreds. (#6263, #6291)
- Fix incorrect comment regarding the functionality of an
if
statement. (#6269) - Update CI to run
isort
over thescripts
andscripts-dev
directories. (#6270) - Replace every instance of
logger.warn
method withlogger.warning
as the former is deprecated. (#6271, #6314) - Port replication http server endpoints to async/await. (#6274)
- Port room rest handlers to async/await. (#6275)
- Remove redundant CLI parameters on CI's
flake8
step. (#6277) - Port
federation_server.py
to async/await. (#6279) - Port receipt and read markers to async/wait. (#6280)
- Split out state storage into separate data store. (#6294, #6295)
- Refactor EventContext for clarity. (#6298)
- Update the version of black used to 19.10b0. (#6304)
- Add some documentation about worker replication. (#6305)
- Move admin endpoints into separate files. Contributed by Awesome Technologies Innovationslabor GmbH. (#6308)
- Document the use of
lint.sh
for code style enforcement & extend it to run on specified paths only. (#6312) - Add optional python dependencies and dependant binary libraries to snapcraft packaging. (#6317)
- Remove the dependency on psutil and replace functionality with the stdlib
resource
module. (#6318, #6336) - Improve documentation for EventContext fields. (#6319)
- Add some checks that we aren't using state from rejected events. (#6330)
- Add continuous integration for python 3.8. (#6341)
- Correct spacing/case of various instances of the word "homeserver". (#6357)
- Temporarily blacklist the failing unit test PurgeRoomTestCase.test_purge_room. (#6361)
Synapse 1.5.1 (2019-11-06)
Features
Synapse 1.5.0 (2019-10-29)
Security updates
This release includes a security fix (#6262, below). Administrators are encouraged to upgrade as soon as possible.
Bugfixes
- Fix bug where room directory search was case sensitive. (#6268)
Synapse 1.5.0rc2 (2019-10-28)
Bugfixes
- Update list of boolean columns in
synapse_port_db
. (#6247) - Fix /keys/query API on workers. (#6256)
- Improve signature checking on some federation APIs. (#6262)
Internal Changes
- Move schema delta files to the correct data store. (#6248)
- Small performance improvement by removing repeated config lookups in room stats calculation. (#6255)
Synapse 1.5.0rc1 (2019-10-24)
Features
- Improve quality of thumbnails for 1-bit/8-bit color palette images. (#2142)
- Add ability to upload cross-signing signatures. (#5726)
- Allow uploading of cross-signing keys. (#5769)
- CAS login now provides a default display name for users if a
displayname_attribute
is set in the configuration file. (#6114) - Reject all pending invites for a user during deactivation. (#6125)
- Add config option to suppress client side resource limit alerting. (#6173)
Bugfixes
- Return an HTTP 404 instead of 400 when requesting a filter by ID that is unknown to the server. Thanks to @krombel for contributing this! (#2380)
- Fix a bug where users could be invited twice to the same group. (#3436)
- Fix
/createRoom
failing with badly-formatted MXIDs in the invitee list. Thanks to @wener291! (#4088) - Make the
synapse_port_db
script create the right indexes on a new PostgreSQL database. (#6102, #6178, #6243) - Fix bug when uploading a large file: Synapse responds with
M_UNKNOWN
while it should beM_TOO_LARGE
according to spec. Contributed by Anshul Angaria. (#6109) - Fix user push rules being deleted from a room when it is upgraded. (#6144)
- Don't 500 when trying to exchange a revoked 3PID invite. (#6147)
- Fix transferring notifications and tags when joining an upgraded room that is new to your server. (#6155)
- Fix bug where guest account registration can wedge after restart. (#6161)
- Fix monthly active user reaping when reserved users are specified. (#6168)
- Fix
/federation/v1/state
endpoint not supporting newer room versions. (#6170) - Fix bug where we were updating censored events as bytes rather than text, occaisonally causing invalid JSON being inserted breaking APIs that attempted to fetch such events. (#6186)
- Fix occasional missed updates in the room and user directories. (#6187)
- Fix tracing of non-JSON APIs,
/media
,/key
etc. (#6195) - Fix bug where presence would not get timed out correctly if a synchrotron worker is used and restarted. (#6212)
- synapse_port_db: Add 2 additional BOOLEAN_COLUMNS to be able to convert from database schema v56. (#6216)
- Fix a bug where the Synapse demo script blacklisted
::1
(ipv6 localhost) from receiving federation traffic. (#6229)
Updates to the Docker image
- Fix logging getting lost for the docker image. (#6197)
Internal Changes
- Update
user_filters
table to have a unique index, and non-null columns. Thanks to @pik for contributing this. (#1172, #6175, #6184) - Allow devices to be marked as hidden, for use by features such as cross-signing. This adds a new field with a default value to the devices field in the database, and so the database upgrade may take a long time depending on how many devices are in the database. (#5759)
- Move lookup-related functions from RoomMemberHandler to IdentityHandler. (#5978)
- Improve performance of the public room list directory. (#6019, #6152, #6153, #6154)
- Edit header dicts docstrings in
SimpleHttpClient
to note thatstr
orbytes
can be passed as header keys. (#6077) - Add snapcraft packaging information. Contributed by @devec0. (#6084, #6191)
- Kill off half-implemented password-reset via sms. (#6101)
- Remove
get_user_by_req
opentracing span and add some tags. (#6108) - Drop some unused database tables. (#6115)
- Add env var to turn on tracking of log context changes. (#6127)
- Refactor configuration loading to allow better typechecking. (#6137)
- Log responder when responding to media request. (#6139)
- Improve performance of
find_next_generated_user_id
DB query. (#6148) - Expand type-checking on modules imported by
synapse.config
. (#6150) - Use Postgres ANY for selecting many values. (#6156)
- Add more caching to
_get_joined_users_from_context
DB query. (#6159) - Add some metrics on the federation sender. (#6160)
- Add some logging to the rooms stats updates, to try to track down a flaky test. (#6167)
- Remove unused
timeout
parameter from_get_public_room_list
. (#6179) - Reject (accidental) attempts to insert bytes into postgres tables. (#6186)
- Make
version
optional in body ofPUT /room_keys/version/{version}
, since it's redundant. (#6189) - Make storage layer responsible for adding device names to key, rather than the handler. (#6193)
- Port
synapse.rest.admin
module to use async/await. (#6196) - Enforce that all boolean configuration values are lowercase in CI. (#6203)
- Remove some unused event-auth code. (#6214)
- Remove
Auth.check
method. (#6217) - Remove
format_tap.py
script in favour of a perl reimplementation in Sytest's repo. (#6219) - Refactor storage layer in preparation to support having multiple databases. (#6231)
- Remove some extra quotation marks across the codebase. (#6236)
Synapse 1.4.1 (2019-10-18)
No changes since 1.4.1rc1.
Synapse 1.4.1rc1 (2019-10-17)
Bugfixes
- Fix bug where redacted events were sometimes incorrectly censored in the database, breaking APIs that attempted to fetch such events. (#6185, 5b0e9948)
Synapse 1.4.0 (2019-10-03)
Bugfixes
- Redact
client_secret
in server logs. (#6158)
Synapse 1.4.0rc2 (2019-10-02)
Bugfixes
- Fix bug in background update that adds last seen information to the
devices
table, and improve its performance on Postgres. (#6135) - Fix bad performance of censoring redactions background task. (#6141)
- Fix fetching censored redactions from DB, which caused APIs like initial sync to fail if it tried to include the censored redaction. (#6145)
- Fix exceptions when storing large retry intervals for down remote servers. (#6146)
Internal Changes
- Fix up sample config entry for
redaction_retention_period
option. (#6117)
Synapse 1.4.0rc1 (2019-09-26)
Note that this release includes significant changes around 3pid verification. Administrators are reminded to review the upgrade notes.
Features
- Changes to 3pid verification:
- Add the ability to send registration emails from the homeserver rather than delegating to an identity server. (#5835, #5940, #5993, #5994, #5868)
- Replace
trust_identity_server_for_password_resets
config option withaccount_threepid_delegates
, and make theid_server
parameteter optional on*/requestToken
endpoints, as per MSC2263. (#5876, #5969, #6028) - Switch to using the v2 Identity Service
/lookup
API where available, with fallback to v1. (Implements MSC2134 plusid_access_token authentication
for v2 Identity Service APIs from MSC2140). (#5897) - Remove
bind_email
andbind_msisdn
parameters from/register
ala MSC2140. (#5964) - Add
m.id_access_token
tounstable_features
in/versions
as per MSC2264. (#5974) - Use the v2 Identity Service API for 3PID invites. (#5979)
- Add
POST /_matrix/client/unstable/account/3pid/unbind
endpoint from MSC2140 for unbinding a 3PID from an identity server without removing it from the homeserver user account. (#5980, #6062) - Use
account_threepid_delegate.email
andaccount_threepid_delegate.msisdn
for validating threepid sessions. (#6011) - Allow homeserver to handle or delegate email validation when adding an email to a user's account. (#6042)
- Implement new Client Server API endpoints
/account/3pid/add
and/account/3pid/bind
as per MSC2290. (#6043) - Add an unstable feature flag for separate add/bind 3pid APIs. (#6044)
- Remove
bind
parameter from Client Server POST/account
endpoint as per MSC2290. (#6067) - Add
POST /add_threepid/msisdn/submit_token
endpoint for proxying submitToken on anaccount_threepid_handler
. (#6078) - Add
submit_url
response parameter to*/msisdn/requestToken
endpoints. (#6079) - Add
m.require_identity_server
flag to /version's unstable_features. (#5972)
- Enhancements to OpenTracing support:
- Make OpenTracing work in worker mode. (#5771)
- Pass OpenTracing contexts between servers when transmitting EDUs. (#5852)
- OpenTracing for device list updates. (#5853)
- Add a tag recording a request's authenticated entity and corresponding servlet in OpenTracing. (#5856)
- Add minimum OpenTracing for client servlets. (#5983)
- Check at setup that OpenTracing is installed if it's enabled in the config. (#5985)
- Trace replication send times. (#5986)
- Include missing OpenTracing contexts in outbout replication requests. (#5982)
- Fix sending of EDUs when OpenTracing is enabled with an empty whitelist. (#5984)
- Fix invalid references to None while OpenTracing if the log context slips. (#5988, #5991)
- OpenTracing for room and e2e keys. (#5855)
- Add OpenTracing span over HTTP push processing. (#6003)
- Add an admin API to purge old rooms from the database. (#5845)
- Retry well-known lookups if we have recently seen a valid well-known record for the server. (#5850)
- Add support for filtered room-directory search requests over federation (MSC2197, in order to allow upcoming room directory query performance improvements. (#5859)
- Correctly retry all hosts returned from SRV when we fail to connect. (#5864)
- Add admin API endpoint for setting whether or not a user is a server administrator. (#5878)
- Enable cleaning up extremities with dummy events by default to prevent undue build up of forward extremities. (#5884)
- Add config option to sign remote key query responses with a separate key. (#5895)
- Add support for config templating. (#5900)
- Users with the type of "support" or "bot" are no longer required to consent. (#5902)
- Let synctl accept a directory of config files. (#5904)
- Increase max display name size to 256. (#5906)
- Add admin API endpoint for getting whether or not a user is a server administrator. (#5914)
- Redact events in the database that have been redacted for a week. (#5934)
- New prometheus metrics:
synapse_federation_known_servers
: represents the total number of servers your server knows about (i.e. is in rooms with), including itself. Enable by settingmetrics_flags.known_servers
to True in the configuration.(#5981)synapse_build_info
: exposes the Python version, OS version, and Synapse version of the running server. (#6005)
- Give appropriate exit codes when synctl fails. (#5992)
- Apply the federation blacklist to requests to identity servers. (#6000)
- Add
report_stats_endpoint
option to configure where stats are reported to, if enabled. Contributed by @Sorunome. (#6012) - Add config option to increase ratelimits for room admins redacting messages. (#6015)
- Stop sending federation transactions to servers which have been down for a long time. (#6026)
- Make the process for mapping SAML2 users to matrix IDs more flexible. (#6037)
- Return a clearer error message when a timeout occurs when attempting to contact an identity server. (#6073)
- Prevent password reset's submit_token endpoint from accepting trailing slashes. (#6074)
- Return 403 on
/register/available
if registration has been disabled. (#6082) - Explicitly log when a homeserver does not have the
trusted_key_servers
config field configured. (#6090) - Add support for pruning old rows in
user_ips
table. (#6098)
Bugfixes
- Don't create broken room when
power_level_content_override.users
does not containcreator_id
. (#5633) - Fix database index so that different backup versions can have the same sessions. (#5857)
- Fix Synapse looking for config options
password_reset_failure_template
andpassword_reset_success_template
, when they are actuallypassword_reset_template_failure_html
,password_reset_template_success_html
. (#5863) - Fix stack overflow when recovering an appservice which had an outage. (#5885)
- Fix error message which referred to
public_base_url
instead ofpublic_baseurl
. Thanks to @aaronraimist for the fix! (#5909) - Fix 404 for thumbnail download when
dynamic_thumbnails
isfalse
and the thumbnail was dynamically generated. Fix reported by rkfg. (#5915) - Fix a cache-invalidation bug for worker-based deployments. (#5920)
- Fix admin API for listing media in a room not being available with an external media repo. (#5966)
- Fix list media admin API always returning an error. (#5967)
- Fix room and user stats tracking. (#5971, #5998, #6029)
- Return a
M_MISSING_PARAM
ifsid
is not provided to/account/3pid
. (#5995) federation_certificate_verification_whitelist
now will not causeTypeErrors
to be raised (a regression in 1.3). Additionally, it now supports internationalised domain names in their non-canonical representation. (#5996)- Only count real users when checking for auto-creation of auto-join room. (#6004)
- Ensure support users can be registered even if MAU limit is reached. (#6020)
- Fix bug where login error was shown incorrectly on SSO fallback login. (#6024)
- Fix bug in calculating the federation retry backoff period. (#6025)
- Prevent exceptions being logged when extremity-cleanup events fail due to lack of user consent to the terms of service. (#6053)
- Remove POST method from password-reset
submit_token
endpoint until we implementsubmit_url
functionality. (#6056) - Fix logcontext spam on non-Linux platforms. (#6059)
- Ensure query parameters in email validation links are URL-encoded. (#6063)
- Fix a bug which caused SAML attribute maps to be overridden by defaults. (#6069)
- Fix the logged number of updated items for the
users_set_deactivated_flag
background update. (#6092) - Add
sid
tonext_link
for email validation. (#6097) - Threepid validity checks on msisdns should not be dependent on
threepid_behaviour_email
. (#6104) - Ensure that servers which are not configured to support email address verification do not offer it in the registration flows. (#6107)
Updates to the Docker image
- Avoid changing
UID/GID
if they are already correct. (#5970) - Provide
SYNAPSE_WORKER
envvar to specify python module. (#6058)
Improved Documentation
- Convert documentation to markdown (from rst) (#5849)
- Update
INSTALL.md
to say that Python 2 is no longer supported. (#5953) - Add developer documentation for using SAML2. (#6032)
- Add some notes on rolling back to v1.3.1. (#6049)
- Update the upgrade notes. (#6050)
Deprecations and Removals
- Remove shared-secret registration from
/_matrix/client/r0/register
endpoint. Contributed by Awesome Technologies Innovationslabor GmbH. (#5877) - Deprecate the
trusted_third_party_id_servers
option. (#5875)
Internal Changes
- Lay the groundwork for structured logging output. (#5680)
- Retry well-known lookup before the cache expires, giving a grace period where the remote well-known can be down but we still use the old result. (#5844)
- Remove log line for debugging issue #5407. (#5860)
- Refactor the Appservice scheduler code. (#5886)
- Compatibility with v2 Identity Service APIs other than /lookup. (#5892, #6013)
- Stop populating some unused tables. (#5893, #6047)
- Add missing index on
users_in_public_rooms
to improve the performance of directory queries. (#5894) - Improve the logging when we have an error when fetching signing keys. (#5896)
- Add support for database engine-specific schema deltas, based on file extension. (#5911)
- Update Buildkite pipeline to use plugins instead of buildkite-agent commands. (#5922)
- Add link in sample config to the logging config schema. (#5926)
- Remove unnecessary parentheses in return statements. (#5931)
- Remove unused
jenkins/prepare_sytest.sh
file. (#5938) - Move Buildkite pipeline config to the pipelines repo. (#5943)
- Remove unnecessary return statements in the codebase which were the result of a regex run. (#5962)
- Remove left-over methods from v1 registration API. (#5963)
- Cleanup event auth type initialisation. (#5975)
- Clean up dependency checking at setup. (#5989)
- Update OpenTracing docs to use the unified
trace
method. (#5776) - Small refactor of function arguments and docstrings in
RoomMemberHandler
. (#6009) - Remove unused
origin
argument onFederationHandler.add_display_name_to_third_party_invite
. (#6010) - Add a
failure_ts
column to thedestinations
database table. (#6016, #6072) - Clean up some code in the retry logic. (#6017)
- Fix the structured logging tests stomping on the global log configuration for subsequent tests. (#6023)
- Clean up the sample config for SAML authentication. (#6064)
- Change mailer logging to reflect Synapse doesn't just do chat notifications by email now. (#6075)
- Move last-seen info into devices table. (#6089)
- Remove unused parameter to
get_user_id_by_threepid
. (#6099) - Refactor the user-interactive auth handling. (#6105)
- Refactor code for calculating registration flows. (#6106)
Synapse 1.3.1 (2019-08-17)
Features
- Drop hard dependency on
sdnotify
python package. (#5871)
Bugfixes
- Fix startup issue (hang on ACME provisioning) due to ordering of Twisted reactor startup. Thanks to @chrismoos for supplying the fix. (#5867)
Synapse 1.3.0 (2019-08-15)
Bugfixes
- Fix 500 Internal Server Error on
publicRooms
when the public room list was cached. (#5851)
Synapse 1.3.0rc1 (2019-08-13)
Features
- Use
M_USER_DEACTIVATED
instead ofM_UNKNOWN
for errcode when a deactivated user attempts to login. (#5686) - Add sd_notify hooks to ease systemd integration and allows usage of Type=Notify. (#5732)
- Synapse will no longer serve any media repo admin endpoints when
enable_media_repo
is set to False in the configuration. If a media repo worker is used, the admin APIs relating to the media repo will be served from it instead. (#5754, #5848) - Synapse can now be configured to not join remote rooms of a given "complexity" (currently, state events) over federation. This option can be used to prevent adverse performance on resource-constrained homeservers. (#5783)
- Allow defining HTML templates to serve the user on account renewal attempt when using the account validity feature. (#5807)
Bugfixes
- Fix UISIs during homeserver outage. (#5693, #5789)
- Fix stack overflow in server key lookup code. (#5724)
- start.sh no longer uses deprecated cli option. (#5725)
- Log when we receive an event receipt from an unexpected origin. (#5743)
- Fix debian packaging scripts to correctly build sid packages. (#5775)
- Correctly handle redactions of redactions. (#5788)
- Return 404 instead of 403 when accessing /rooms/{roomId}/event/{eventId} for an event without the appropriate permissions. (#5798)
- Fix check that tombstone is a state event in push rules. (#5804)
- Fix error when trying to login as a deactivated user when using a worker to handle login. (#5806)
- Fix bug where user
/sync
stream could get wedged in rare circumstances. (#5825) - The purge_remote_media.sh script was fixed. (#5839)
Deprecations and Removals
- Synapse now no longer accepts the
-v
/--verbose
,-f
/--log-file
, or--log-config
command line flags, and removes the deprecatedverbose
andlog_file
configuration file options. Users of these options should migrate their options into the dedicated log configuration. (#5678, #5729) - Remove non-functional 'expire_access_token' setting. (#5782)
Internal Changes
- Make Jaeger fully configurable. (#5694)
- Add precautionary measures to prevent future abuse of
window.opener
in default welcome page. (#5695) - Reduce database IO usage by optimising queries for current membership. (#5706, #5738, #5746, #5752, #5770, #5774, #5792, #5793)
- Improve caching when fetching
get_filtered_current_state_ids
. (#5713) - Don't accept opentracing data from clients. (#5715)
- Speed up PostgreSQL unit tests in CI. (#5717)
- Update the coding style document. (#5719)
- Improve database query performance when recording retry intervals for remote hosts. (#5720)
- Add a set of opentracing utils. (#5722)
- Cache result of get_version_string to reduce overhead of
/version
federation requests. (#5730) - Return 'user_type' in admin API user endpoints results. (#5731)
- Don't package the sytest test blacklist file. (#5733)
- Replace uses of returnValue with plain return, as returnValue is not needed on Python 3. (#5736)
- Blacklist some flakey tests in worker mode. (#5740)
- Fix some error cases in the caching layer. (#5749)
- Add a prometheus metric for pending cache lookups. (#5750)
- Stop trying to fetch events with event_id=None. (#5753)
- Convert RedactionTestCase to modern test style. (#5768)
- Allow looping calls to be given arguments. (#5780)
- Set the logs emitted when checking typing and presence timeouts to DEBUG level, not INFO. (#5785)
- Remove DelayedCall debugging from the test suite, as it is no longer required in the vast majority of Synapse's tests. (#5787)
- Remove some spurious exceptions from the logs where we failed to talk to a remote server. (#5790)
- Improve performance when making
.well-known
requests by sharing the SSL options between requests. (#5794) - Disable codecov GitHub comments on PRs. (#5796)
- Don't allow clients to send tombstone events that reference the room it's sent in. (#5801)
- Deny redactions of events sent in a different room. (#5802)
- Deny sending well known state types as non-state events. (#5805)
- Handle incorrectly encoded query params correctly by returning a 400. (#5808)
- Handle pusher being deleted during processing rather than logging an exception. (#5809)
- Return 502 not 500 when failing to reach any remote server. (#5810)
- Reduce global pauses in the events stream caused by expensive state resolution during persistence. (#5826)
- Add a lower bound to well-known lookup cache time to avoid repeated lookups. (#5836)
- Whitelist history visbility sytests in worker mode tests. (#5843)
Synapse 1.2.1 (2019-07-26)
Security update
This release includes four security fixes:
- Prevent an attack where a federated server could send redactions for arbitrary events in v1 and v2 rooms. (#5767)
- Prevent a denial-of-service attack where cycles of redaction events would make Synapse spin infinitely. Thanks to
@lrizika:matrix.org
for identifying and responsibly disclosing this issue. (0f2ecb961) - Prevent an attack where users could be joined or parted from public rooms without their consent. Thanks to @dylangerdaly for identifying and responsibly disclosing this issue. (#5744)
- Fix a vulnerability where a federated server could spoof read-receipts from users on other servers. Thanks to @dylangerdaly for identifying this issue too. (#5743)
Additionally, the following fix was in Synapse 1.2.0, but was not correctly identified during the original release:
- It was possible for a room moderator to send a redaction for an
m.room.create
event, which would downgrade the room to version 1. Thanks to/dev/ponies
for identifying and responsibly disclosing this issue! (#5701)
Synapse 1.2.0 (2019-07-25)
No significant changes.
Synapse 1.2.0rc2 (2019-07-24)
Bugfixes
- Fix a regression introduced in v1.2.0rc1 which led to incorrect labels on some prometheus metrics. (#5734)
Synapse 1.2.0rc1 (2019-07-22)
Security fixes
This update included a security fix which was initially incorrectly flagged as a regular bug fix.
- It was possible for a room moderator to send a redaction for an
m.room.create
event, which would downgrade the room to version 1. Thanks to/dev/ponies
for identifying and responsibly disclosing this issue! (#5701)
Features
- Add support for opentracing. (#5544, #5712)
- Add ability to pull all locally stored events out of synapse that a particular user can see. (#5589)
- Add a basic admin command app to allow server operators to run Synapse admin commands separately from the main production instance. (#5597)
- Add
sender
andorigin_server_ts
fields tom.replace
. (#5613) - Add default push rule to ignore reactions. (#5623)
- Include the original event when asking for its relations. (#5626)
- Implement
session_lifetime
configuration option, after which access tokens will expire. (#5660) - Return "This account has been deactivated" when a deactivated user tries to login. (#5674)
- Enable aggregations support by default (#5714)
Bugfixes
- Fix 'utime went backwards' errors on daemonization. (#5609)
- Various minor fixes to the federation request rate limiter. (#5621)
- Forbid viewing relations on an event once it has been redacted. (#5629)
- Fix requests to the
/store_invite
endpoint of identity servers being sent in the wrong format. (#5638) - Fix newly-registered users not being able to lookup their own profile without joining a room. (#5644)
- Fix bug in #5626 that prevented the original_event field from actually having the contents of the original event in a call to
/relations
. (#5654) - Fix 3PID bind requests being sent to identity servers as
application/x-form-www-urlencoded
data, which is deprecated. (#5658) - Fix some problems with authenticating redactions in recent room versions. (#5699, #5700, #5707)
Updates to the Docker image
- Base Docker image on a newer Alpine Linux version (3.8 -> 3.10). (#5619)
- Add missing space in default logging file format generated by the Docker image. (#5620)
Improved Documentation
- Add information about nginx normalisation to reverse_proxy.rst. Contributed by @skalarproduktraum - thanks! (#5397)
- --no-pep517 should be --no-use-pep517 in the documentation to setup the development environment. (#5651)
- Improvements to Postgres setup instructions. Contributed by @Lrizika - thanks! (#5661)
- Minor tweaks to postgres documentation. (#5675)
Deprecations and Removals
- Remove support for the
invite_3pid_guest
configuration setting. (#5625)
Internal Changes
- Move logging code out of
synapse.util
and intosynapse.logging
. (#5606, #5617) - Add a blacklist file to the repo to blacklist certain sytests from failing CI. (#5611)
- Make runtime errors surrounding password reset emails much clearer. (#5616)
- Remove dead code for persiting outgoing federation transactions. (#5622)
- Add
lint.sh
to the scripts-dev folder which will run all linting steps required by CI. (#5627) - Move RegistrationHandler.get_or_create_user to test code. (#5628)
- Add some more common python virtual-environment paths to the black exclusion list. (#5630)
- Some counter metrics exposed over Prometheus have been renamed, with the old names preserved for backwards compatibility and deprecated. See
docs/metrics-howto.rst
for details. (#5636) - Unblacklist some user_directory sytests. (#5637)
- Factor out some redundant code in the login implementation. (#5639)
- Update ModuleApi to avoid register(generate_token=True). (#5640)
- Remove access-token support from
RegistrationHandler.register
, and rename it. (#5641) - Remove access-token support from
RegistrationStore.register
, and rename it. (#5642) - Improve logging for auto-join when a new user is created. (#5643)
- Remove unused and unnecessary check for FederationDeniedError in _exception_to_failure. (#5645)
- Fix a small typo in a code comment. (#5655)
- Clean up exception handling around client access tokens. (#5656)
- Add a mechanism for per-test homeserver configuration in the unit tests. (#5657)
- Inline issue_access_token. (#5659)
- Update the sytest BuildKite configuration to checkout Synapse in
/src
. (#5664) - Add a
docker
type to the towncrier configuration. (#5673) - Convert
synapse.federation.transport.server
toasync
. Might improve some stack traces. (#5689) - Documentation for opentracing. (#5703)
Synapse 1.1.0 (2019-07-04)
As of v1.1.0, Synapse no longer supports Python 2, nor Postgres version 9.4. See the upgrade notes for more details.
This release also deprecates the use of environment variables to configure the docker image. See the docker README for more details.
No changes since 1.1.0rc2.
Synapse 1.1.0rc2 (2019-07-03)
Bugfixes
- Fix regression in 1.1rc1 where OPTIONS requests to the media repo would fail. (#5593)
- Removed the
SYNAPSE_SMTP_*
docker container environment variables. Using these environment variables prevented the docker container from starting in Synapse v1.0, even though they didn't actually allow any functionality anyway. (#5596) - Fix a number of "Starting txn from sentinel context" warnings. (#5605)
Internal Changes
- Update github templates. (#5552)
Synapse 1.1.0rc1 (2019-07-02)
As of v1.1.0, Synapse no longer supports Python 2, nor Postgres version 9.4. See the upgrade notes for more details.
Features
- Added possibilty to disable local password authentication. Contributed by Daniel Hoffend. (#5092)
- Add monthly active users to phonehome stats. (#5252)
- Allow expired user to trigger renewal email sending manually. (#5363)
- Statistics on forward extremities per room are now exposed via Prometheus. (#5384, #5458, #5461)
- Add --no-daemonize option to run synapse in the foreground, per issue #4130. Contributed by Soham Gumaste. (#5412, #5587)
- Fully support SAML2 authentication. Contributed by Alexander Trost - thank you! (#5422)
- Allow server admins to define implementations of extra rules for allowing or denying incoming events. (#5440, #5474, #5477)
- Add support for handling pagination APIs on client reader worker. (#5505, #5513, #5531)
- Improve help and cmdline option names for --generate-config options. (#5512)
- Allow configuration of the path used for ACME account keys. (#5516, #5521, #5522)
- Add --data-dir and --open-private-ports options. (#5524)
- Split public rooms directory auth config in two settings, in order to manage client auth independently from the federation part of it. Obsoletes the "restrict_public_rooms_to_local_users" configuration setting. If "restrict_public_rooms_to_local_users" is set in the config, Synapse will act as if both new options are enabled, i.e. require authentication through the client API and deny federation requests. (#5534)
- The minimum TLS version used for outgoing federation requests can now be set with
federation_client_minimum_tls_version
. (#5550) - Optimise devices changed query to not pull unnecessary rows from the database, reducing database load. (#5559)
- Add new metrics for number of forward extremities being persisted and number of state groups involved in resolution. (#5476)
Bugfixes
- Fix bug processing incoming events over federation if call to
/get_missing_events
fails. (#5042) - Prevent more than one room upgrade happening simultaneously on the same room. (#5051)
- Fix a bug where running synapse_port_db would cause the account validity feature to fail because it didn't set the type of the email_sent column to boolean. (#5325)
- Warn about disabling email-based password resets when a reset occurs, and remove warning when someone attempts a phone-based reset. (#5387)
- Fix email notifications for unnamed rooms with multiple people. (#5388)
- Fix exceptions in federation reader worker caused by attempting to renew attestations, which should only happen on master worker. (#5389)
- Fix handling of failures fetching remote content to not log failures as exceptions. (#5390)
- Fix a bug where deactivated users could receive renewal emails if the account validity feature is on. (#5394)
- Fix missing invite state after exchanging 3PID invites over federaton. (#5464)
- Fix intermittent exceptions on Apple hardware. Also fix bug that caused database activity times to be under-reported in log lines. (#5498)
- Fix logging error when a tampered event is detected. (#5500)
- Fix bug where clients could tight loop calling
/sync
for a period. (#5507) - Fix bug with
jinja2
preventing Synapse from starting. Users who had this problem should now simply need to runpip install matrix-synapse
. (#5514) - Fix a regression where homeservers on private IP addresses were incorrectly blacklisted. (#5523)
- Fixed m.login.jwt using unregistred user_id and added pyjwt>=1.6.4 as jwt conditional dependencies. Contributed by Pau Rodriguez-Estivill. (#5555, #5586)
- Fix a bug that would cause invited users to receive several emails for a single 3PID invite in case the inviter is rate limited. (#5576)
Updates to the Docker image
- Add ability to change Docker containers timezone with the
TZ
variable. (#5383) - Update docker image to use Python 3.7. (#5546)
- Deprecate the use of environment variables for configuration, and make the use of a static configuration the default. (#5561, #5562, #5566, #5567)
- Increase default log level for docker image to INFO. It can still be changed by editing the generated log.config file. (#5547)
- Send synapse logs to the docker logging system, by default. (#5565)
- Open the non-TLS port by default. (#5568)
- Fix failure to start under docker with SAML support enabled. (#5490)
- Use a sensible location for data files when generating a config file. (#5563)
Deprecations and Removals
- Python 2.7 is no longer a supported platform. Synapse now requires Python 3.5+ to run. (#5425)
- PostgreSQL 9.4 is no longer supported. Synapse requires Postgres 9.5+ or above for Postgres support. (#5448)
- Remove support for cpu_affinity setting. (#5525)
Improved Documentation
- Improve README section on performance troubleshooting. (#4276)
- Add information about how to install and run
black
on the codebase to code_style.rst. (#5537) - Improve install docs on choosing server_name. (#5558)
Internal Changes
- Add logging to 3pid invite signature verification. (#5015)
- Update example haproxy config to a more compatible setup. (#5313)
- Track deactivated accounts in the database. (#5378, #5465, #5493)
- Clean up code for sending federation EDUs. (#5381)
- Add a sponsor button to the repo. (#5382, #5386)
- Don't log non-200 responses from federation queries as exceptions. (#5383)
- Update Python syntax in contrib/ to Python 3. (#5446)
- Update federation_client dev script to support
.well-known
and work with python3. (#5447) - SyTest has been moved to Buildkite. (#5459)
- Demo script now uses python3. (#5460)
- Synapse can now handle RestServlets that return coroutines. (#5475, #5585)
- The demo servers talk to each other again. (#5478)
- Add an EXPERIMENTAL config option to try and periodically clean up extremities by sending dummy events. (#5480)
- Synapse's codebase is now formatted by
black
. (#5482) - Some cleanups and sanity-checking in the CPU and database metrics. (#5499)
- Improve email notification logging. (#5502)
- Fix "Unexpected entry in 'full_schemas'" log warning. (#5509)
- Improve logging when generating config files. (#5510)
- Refactor and clean up Config parser for maintainability. (#5511)
- Make the config clearer in that email.template_dir is relative to the Synapse's root directory, not the
synapse/
folder within it. (#5543) - Update v1.0.0 release changelog to include more information about changes to password resets. (#5545)
- Remove non-functioning check_event_hash.py dev script. (#5548)
- Synapse will now only allow TLS v1.2 connections when serving federation, if it terminates TLS. As Synapse's allowed ciphers were only able to be used in TLSv1.2 before, this does not change behaviour. (#5550)
- Logging when running GC collection on generation 0 is now at the DEBUG level, not INFO. (#5557)
- Reduce the amount of stuff we send in the docker context. (#5564)
- Point the reverse links in the Purge History contrib scripts at the intended location. (#5570)
Synapse 1.0.0 (2019-06-11)
Bugfixes
- Fix bug where attempting to send transactions with large number of EDUs can fail. (#5418)
Improved Documentation
- Expand the federation guide to include relevant content from the MSC1711 FAQ (#5419)
Internal Changes
- Move password reset links to /_matrix/client/unstable namespace. (#5424)
Synapse 1.0.0rc3 (2019-06-10)
Security: Fix authentication bug introduced in 1.0.0rc1. Please upgrade to rc3 immediately
Synapse 1.0.0rc2 (2019-06-10)
Bugfixes
- Remove redundant warning about key server response validation. (#5392)
- Fix bug where old keys stored in the database with a null valid until timestamp caused all verification requests for that key to fail. (#5415)
- Fix excessive memory using with default
federation_verify_certificates: true
configuration. (#5417)
Synapse 1.0.0rc1 (2019-06-07)
Features
-
Synapse now more efficiently collates room statistics. (#4338, #5260, #5324)
-
Add experimental support for relations (aka reactions and edits). (#5220)
-
Allow configuring a range for the account validity startup job. (#5276)
-
CAS login will now hit the r0 API, not the deprecated v1 one. (#5286)
-
Validate federation server TLS certificates by default (implements MSC1711). (#5359)
-
Update /_matrix/client/versions to reference support for r0.5.0. (#5360)
-
Add a script to generate new signing-key files. (#5361)
-
Update upgrade and installation guides ahead of 1.0. (#5371)
-
Replace the
perspectives
configuration section withtrusted_key_servers
, and make validating the signatures on responses optional (since TLS will do this job for us). (#5374) -
Add ability to perform password reset via email without trusting the identity server. As a result of this PR, password resets will now be disabled on the default configuration.
Password reset emails are now sent from the homeserver by default, instead of the identity server. To enable this functionality, ensure
email
andpublic_baseurl
config options are filled out.If you would like to re-enable password resets being sent from the identity server (warning: this is dangerous! See #5345), set
email.trust_identity_server_for_password_resets
to true. (#5377) -
Set default room version to v4. (#5379)
Bugfixes
- Fixes client-server API not sending "m.heroes" to lazy-load /sync requests when a rooms name or its canonical alias are empty. Thanks to @dnaf for this work! (#5089)
- Prevent federation device list updates breaking when processing multiple updates at once. (#5156)
- Fix worker registration bug caused by ClientReaderSlavedStore being unable to see get_profileinfo. (#5200)
- Fix race when backfilling in rooms with worker mode. (#5221)
- Fix appservice timestamp massaging. (#5233)
- Ensure that server_keys fetched via a notary server are correctly signed. (#5251)
- Show the correct error when logging out and access token is missing. (#5256)
- Fix error code when there is an invalid parameter on /_matrix/client/r0/publicRooms (#5257)
- Fix error when downloading thumbnail with missing width/height parameter. (#5258)
- Fix schema update for account validity. (#5268)
- Fix bug where we leaked extremities when we soft failed events, leading to performance degradation. (#5274, #5278, #5291)
- Fix "db txn 'update_presence' from sentinel context" log messages. (#5275)
- Fix dropped logcontexts during high outbound traffic. (#5277)
- Fix a bug where it is not possible to get events in the federation format with the request
GET /_matrix/client/r0/rooms/{roomId}/messages
. (#5293) - Fix performance problems with the rooms stats background update. (#5294)
- Fix noisy 'no key for server' logs. (#5300)
- Fix bug where a notary server would sometimes forget old keys. (#5307)
- Prevent users from setting huge displaynames and avatar URLs. (#5309)
- Fix handling of failures when processing incoming events where calling
/event_auth
on remote server fails. (#5317) - Ensure that we have an up-to-date copy of the signing key when validating incoming federation requests. (#5321)
- Fix various problems which made the signing-key notary server time out for some requests. (#5333)
- Fix bug which would make certain operations (such as room joins) block for 20 minutes while attemoting to fetch verification keys. (#5334)
- Fix a bug where we could rapidly mark a server as unreachable even though it was only down for a few minutes. (#5335, #5340)
- Fix a bug where account validity renewal emails could only be sent when email notifs were enabled. (#5341)
- Fix failure when fetching batches of events during backfill, etc. (#5342)
- Add a new room version where the timestamps on events are checked against the validity periods on signing keys. (#5348, #5354)
- Fix room stats and presence background updates to correctly handle missing events. (#5352)
- Include left members in room summaries' heroes. (#5355)
- Fix
federation_custom_ca_list
configuration option. (#5362) - Fix missing logcontext warnings on shutdown. (#5369)
Improved Documentation
Internal Changes
- Synapse will now serve the experimental "room complexity" API endpoint. (#5216)
- The base classes for the v1 and v2_alpha REST APIs have been unified. (#5226, #5328)
- Simplifications and comments in do_auth. (#5227)
- Remove urllib3 pin as requests 2.22.0 has been released supporting urllib3 1.25.2. (#5230)
- Preparatory work for key-validity features. (#5232, #5234, #5235, #5236, #5237, #5244, #5250, #5296, #5299, #5343, #5347, #5356)
- Specify the type of reCAPTCHA key to use. (#5283)
- Improve sample config for monthly active user blocking. (#5284)
- Remove spurious debug from MatrixFederationHttpClient.get_json. (#5287)
- Improve logging for logcontext leaks. (#5288)
- Clarify that the admin change password API logs the user out. (#5303)
- New installs will now use the v54 full schema, rather than the full schema v14 and applying incremental updates to v54. (#5320)
- Improve docstrings on MatrixFederationClient. (#5332)
- Clean up FederationClient.get_events for clarity. (#5344)
- Various improvements to debug logging. (#5353)
- Don't run CI build checks until sample config check has passed. (#5370)
- Automatically retry buildkite builds (max twice) when an agent is lost. (#5380)