This release removes using the deprecated direct TCP replication configuration for workers. Server admins should use Redis instead. See the upgrade notes.
The minimum version of poetry
supported for managing source checkouts is now
1.2.0.
Notice: from the next major release (1.68.0) installing Synapse from a source
checkout will require a recent Rust compiler. Those using packages or
pip install matrix-synapse
will not be affected. See the upgrade
notes.
Notice: from the next major release (1.68.0), running Synapse with a SQLite database will require SQLite version 3.27.0 or higher. (The current minimum version is SQLite 3.22.0.) See #12983 and the upgrade notes for more details.
No significant changes since 1.67.0rc1.
- Support setting the registration shared secret in a file, via a new
registration_shared_secret_path
configuration option. (#13614) - Change the default startup behaviour so that any missing "additional" configuration files (signing key, etc) are generated automatically. (#13615)
- Improve performance of sending messages in rooms with thousands of local users. (#13634)
- Fix a bug introduced in Synapse 1.13 where the List Rooms admin API would return integers instead of booleans for the
federatable
andpublic
fields when using a Sqlite database. (#13509) - Fix bug that user cannot
/forget
rooms after the last member has left the room. (#13546) - Faster Room Joins: fix
/make_knock
blocking indefinitely when the room in question is a partial-stated room. (#13583) - Fix loading the current stream position behind the actual position. (#13585)
- Fix a longstanding bug in
register_new_matrix_user
which meant it was always necessary to explicitly give a server URL. (#13616) - Fix the running of MSC1763 retention purge_jobs in deployments with background jobs running on a worker by forcing them back onto the main worker. Contributed by Brad @ Beeper. (#13632)
- Fix a long-standing bug that downloaded media for URL previews was not deleted while database background updates were running. (#13657)
- Fix MSC3030
/timestamp_to_event
endpoint to return the correct next event when the events have the same timestamp. (#13658) - Fix bug where we wedge media plugins if clients disconnect early. Introduced in v1.22.0. (#13660)
- Fix a long-standing bug which meant that keys for unwhitelisted servers were not returned by
/_matrix/key/v2/query
. (#13683) - Fix a bug introduced in Synapse v1.20.0 that would cause the unstable unread counts from MSC2654 to be calculated even if the feature is disabled. (#13694)
- Update docker image to use a stable version of poetry. (#13688)
- Improve the description of the "chain cover index" used internally by Synapse. (#13602)
- Document how "monthly active users" is calculated and used. (#13617)
- Improve documentation around user registration. (#13640)
- Remove documentation of legacy
frontend_proxy
worker app. (#13645) - Clarify documentation that HTTP replication traffic can be protected with a shared secret. (#13656)
- Remove unintentional colons from config manual headers. (#13665)
- Update docs to make enabling metrics more clear. (#13678)
- Clarify
(room_id, event_id)
global uniqueness and how we should scope our database schemas. (#13701)
- Drop support for calling
/_matrix/client/v3/rooms/{roomId}/invite
without anid_access_token
, which was not permitted by the spec. Contributed by @Vetchu. (#13241) - Remove redundant
_get_joined_users_from_context
cache. Contributed by Nick @ Beeper (@fizzadar). (#13569) - Remove the ability to use direct TCP replication with workers. Direct TCP replication was deprecated in Synapse v1.18.0. Workers now require using Redis. (#13647)
- Remove support for unstable private read receipts. (#13653, #13692)
- Extend the release script to wait for GitHub Actions to finish and to be usable as a guide for the whole process. (#13483)
- Add experimental configuration option to allow disabling legacy Prometheus metric names. (#13540)
- Cache user IDs instead of profiles to reduce cache memory usage. Contributed by Nick @ Beeper (@fizzadar). (#13573, #13600)
- Optimize how Synapse calculates domains to fetch from during backfill. (#13575)
- Comment about a better future where we can get the state diff between two events. (#13586)
- Instrument
_check_sigs_and_hash_and_fetch
to trace time spent in child concurrent calls for understandable traces in Jaeger. (#13588) - Improve performance of
@cachedList
. (#13591) - Minor speed up of fetching large numbers of push rules. (#13592)
- Optimise push action fetching queries. Contributed by Nick @ Beeper (@fizzadar). (#13597)
- Rename
event_map
tounpersisted_events
when computing the auth differences. (#13603) - Refactor
get_users_in_room(room_id)
mis-use with dedicatedget_current_hosts_in_room(room_id)
function. (#13605) - Use dedicated
get_local_users_in_room(room_id)
function to find local users when calculatingjoin_authorised_via_users_server
of a/make_join
request. (#13606) - Refactor
get_users_in_room(room_id)
mis-use to lookup single local user with dedicatedcheck_local_user_in_room(...)
function. (#13608) - Drop unused column
application_services_state.last_txn
. (#13627) - Improve readability of Complement CI logs by printing failure results last. (#13639)
- Generalise the
@cancellable
annotation so it can be used on functions other than just servlet methods. (#13662) - Introduce a
CommonUsageMetrics
class to share some usage metrics between the Prometheus exporter and the phone home stats. (#13671) - Add some logging to help track down #13444. (#13679)
- Update poetry lock file for v1.2.0. (#13689)
- Add cache to
is_partial_state_room
. (#13693) - Update the Grafana dashboard that is included with Synapse in the
contrib
directory. (#13697) - Only run trial CI on all python versions on non-PRs. (#13698)
- Fix typechecking with latest types-jsonschema. (#13712)
- Reduce number of CI checks we run for PRs. (#13713)
No significant changes since 1.66.0rc2.
This release removes the ability for homeservers to delegate email ownership verification and password reset confirmation to identity servers. This removal was originally planned for Synapse 1.64, but was later deferred until now. See the upgrade notes for more details.
Deployments with multiple workers should note that the direct TCP replication
configuration was deprecated in Synapse v1.18.0 and will be removed in Synapse
v1.67.0. In particular, the TCP replication
listener
type (not to be confused with the replication
resource on the http
listener
type) and the worker_replication_port
config option will be removed .
To migrate to Redis, add the redis
config,
then remove the TCP replication
listener from config of the master and
worker_replication_port
from worker config. Note that a HTTP listener with a
replication
resource is still required. See the
worker documentation
for more details.
- Fix a bug introduced in Synapse 1.66.0rc1 where the new rate limit metrics were misreported (
synapse_rate_limit_sleep_affected_hosts
,synapse_rate_limit_reject_affected_hosts
). (#13649)
- Improve validation of request bodies for the following client-server API endpoints:
/account/password
,/account/password/email/requestToken
,/account/deactivate
and/account/3pid/email/requestToken
. (#13188, #13563) - Add forgotten status to Room Details Admin API. (#13503)
- Add an experimental implementation for MSC3852 (Expose user agents on
Device
). (#13549) - Add
org.matrix.msc2716v4
experimental room version with updated content fields. Part of MSC2716 (Importing history). (#13551) - Add support for compression to federation responses. (#13537)
- Improve performance of sending messages in rooms with thousands of local users. (#13522, #13547)
- Faster room joins: make
/joined_members
block whilst the room is partial stated. (#13514) - Fix a bug introduced in Synapse 1.21.0 where the
/event_reports
Admin API could return a total count which was larger than the number of results you can actually query for. (#13525) - Fix a bug introduced in Synapse 1.52.0 where sending server notices fails if
max_avatar_size
orallowed_avatar_mimetypes
is set and notsystem_mxid_avatar_url
. (#13566) - Fix a bug where the
opentracing.force_tracing_for_users
config option would not apply to/sendToDevice
and/keys/upload
requests. (#13574)
- Add
openssl
example for generating registration HMAC digest. (#13472) - Tidy up Synapse's README. (#13491)
- Document that event purging related to the
redaction_retention_period
config option is executed only every 5 minutes. (#13492) - Add a warning to retention documentation regarding the possibility of database corruption. (#13497)
- Document that the
DOCKER_BUILDKIT=1
flag is needed to build the docker image. (#13515) - Add missing links in
user_consent
section of configuration manual. (#13536) - Fix the doc and some warnings that were referring to the nonexistent
custom_templates_directory
setting (instead ofcustom_template_directory
). (#13538)
- Remove the ability for homeservers to delegate email ownership verification and password reset confirmation to identity servers. See upgrade notes for more details.
- Update the rejected state of events during de-partial-stating. (#13459)
- Avoid blocking lazy-loading
/sync
s during partial joins due to remote memberships. Pull remote memberships from auth events instead of the room state. (#13477) - Refuse to start when faster joins is enabled on a deployment with workers, since worker configurations are not currently supported. (#13531)
- Allow use of both
@trace
and@tag_args
stacked on the same function. (#13453) - Instrument the federation/backfill part of
/messages
for understandable traces in Jaeger. (#13489) - Instrument
FederationStateIdsServlet
(/state_ids
) for understandable traces in Jaeger. (#13499, #13554) - Track HTTP response times over 10 seconds from
/messages
(synapse_room_message_list_rest_servlet_response_time_seconds
). (#13533) - Add metrics to track how the rate limiter is affecting requests (sleep/reject). (#13534, #13541)
- Add metrics to time how long it takes us to do backfill processing (
synapse_federation_backfill_processing_before_time_seconds
,synapse_federation_backfill_processing_after_time_seconds
). (#13535, #13584) - Add metrics to track rate limiter queue timing (
synapse_rate_limit_queue_wait_time_seconds
). (#13544) - Update metrics to track
/messages
response time by room size. (#13545)
- Refactor methods in
synapse.api.auth.Auth
to useRequester
objects everywhere instead of user IDs. (#13024) - Clean-up tests for notifications. (#13471)
- Add some miscellaneous comments to document sync, especially around
compute_state_delta
. (#13474) - Use literals in place of
HTTPStatus
constants in tests. (#13479, #13488) - Add comments about how event push actions are rotated. (#13485)
- Modify HTML template content to better support mobile devices' screen sizes. (#13493)
- Add a linter script which will reject non-strict types in Pydantic models. (#13502)
- Reduce the number of tests using legacy TCP replication. (#13543)
- Allow specifying additional request fields when using the
HomeServerTestCase.login
helper method. (#13549) - Make
HomeServerTestCase
load any configured homeserver modules automatically. (#13558)
No significant changes since 1.65.0rc2.
- Revert 'Remove the unspecced
room_id
field in the/hierarchy
response. (#13365)' to give more time for clients to update. (#13501)
- Add support for stable prefixes for MSC2285 (private read receipts). (#13273)
- Add new unstable error codes
ORG.MATRIX.MSC3848.ALREADY_JOINED
,ORG.MATRIX.MSC3848.NOT_JOINED
, andORG.MATRIX.MSC3848.INSUFFICIENT_POWER
described in MSC3848. (#13343) - Use stable prefixes for MSC3827. (#13370)
- Add a new module API method to translate a room alias into a room ID. (#13428)
- Add a new module API method to create a room. (#13429)
- Add remote join capability to the module API's
update_room_membership
method (in a backwards compatible manner). (#13441)
- Update the version of the LDAP3 auth provider module included in the
matrixdotorg/synapse
DockerHub images and the Debian packages hosted on packages.matrix.org to 0.2.2. This version fixes a regression in the module. (#13470) - Fix a bug introduced in Synapse v1.41.0 where the
/hierarchy
API returned non-standard information (aroom_id
field under each entry inchildren_state
) (this was reverted in v1.65.0rc2, see changelog notes above). (#13365) - Fix a bug introduced in Synapse 0.24.0 that would respond with the wrong error status code to
/joined_members
requests when the requester is not a current member of the room. Contributed by @andrewdoh. (#13374) - Fix bug in handling of typing events for appservices. Contributed by Nick @ Beeper (@fizzadar). (#13392)
- Fix a bug introduced in Synapse 1.57.0 where rooms listed in
exclude_rooms_from_sync
in the configuration file would not be properly excluded from incremental syncs. (#13408) - Fix a bug in the experimental faster-room-joins support which could cause it to get stuck in an infinite loop. (#13353)
- Faster room joins: fix a bug which caused rejected events to become un-rejected during state syncing. (#13413)
- Faster room joins: fix error when running out of servers to sync partial state with, so that Synapse raises the intended error instead. (#13432)
- Make Docker images build on armv7 by installing cryptography dependencies in the 'requirements' stage. Contributed by Jasper Spaans. (#13372)
- Update the 'registration tokens' page to acknowledge that the relevant MSC was merged into version 1.2 of the Matrix specification. Contributed by @moan0s. (#11897)
- Document which HTTP resources support gzip compression. (#13221)
- Add steps describing how to elevate an existing user to administrator by manipulating the database. (#13230)
- Fix wrong headline for
url_preview_accept_language
in documentation. (#13437) - Remove redundant 'Contents' section from the Configuration Manual. Contributed by @dklimpel. (#13438)
- Update documentation for config setting
macaroon_secret_key
. (#13443) - Update outdated information on
sso_mapping_providers
documentation. (#13449) - Fix example code in module documentation of
password_auth_provider_callbacks
. (#13450) - Make the configuration for the cache clearer. (#13481)
- Extend the release script to automatically push a new SyTest branch, rather than having that be a manual process. (#12978)
- Make minor clarifications to the error messages given when we fail to join a room via any server. (#13160)
- Enable Complement CI tests in the 'latest deps' test run. (#13213)
- Fix long-standing bugged logic which was never hit in
get_pdu
asking every remote destination even after it finds an event. (#13346) - Faster room joins: avoid blocking when pulling events with partially missing prev events. (#13355)
- Instrument
/messages
for understandable traces in Jaeger. (#13368) - Remove an unused argument to
get_relations_for_event
. (#13383) - Add a
merge-back
command to the release script, which automates merging the correct branches after a release. (#13393) - Adding missing type hints to tests. (#13397)
- Faster Room Joins: don't leave a stuck room partial state flag if the join fails. (#13403)
- Refactor
_resolve_state_at_missing_prevs
to compute anEventContext
instead. (#13404, #13431) - Faster Room Joins: prevent Synapse from answering federated join requests for a room which it has not fully joined yet. (#13416)
- Re-enable running Complement tests against Synapse with workers. (#13420)
- Prevent unnecessary lookups to any external
get_event
cache. Contributed by Nick @ Beeper (@fizzadar). (#13435) - Add some tracing to give more insight into local room joins. (#13439)
- Rename class
RateLimitConfig
toRatelimitSettings
andFederationRateLimitConfig
toFederationRatelimitSettings
. (#13442) - Add some comments about how event push actions are stored. (#13445, #13455)
- Improve rebuild speed for the "synapse-workers" docker image. (#13447)
- Fix
@tag_args
being off-by-one with the arguments when tagging a span (tracing). (#13452) - Update type of
EventContext.rejected
. (#13460) - Use literals in place of
HTTPStatus
constants in tests. (#13463, #13469) - Correct a misnamed argument in state res v2 internals. (#13467)
No significant changes since 1.64.0rc2.
Synapse v1.66.0 will remove the ability to delegate the tasks of verifying email address ownership, and password reset confirmation, to an identity server.
If you require your homeserver to verify e-mail addresses or to support password resets via e-mail, please configure your homeserver with SMTP access so that it can send e-mails on its own behalf. Consult the configuration documentation for more information.
This RC reintroduces support for account_threepid_delegates.email
, which was removed in 1.64.0rc1. It remains deprecated and will be removed altogether in Synapse v1.66.0. (#13406)
This RC removed the ability to delegate the tasks of verifying email address ownership, and password reset confirmation, to an identity server.
We have also stopped building .deb
packages for Ubuntu 21.10 as it is no longer an active version of Ubuntu.
- Improve error messages when media thumbnails cannot be served. (#13038)
- Allow pagination from remote event after discovering it from MSC3030
/timestamp_to_event
. (#13205) - Add a
room_type
field in the responses for the list room and room details admin APIs. Contributed by @andrewdoh. (#13208) - Add support for room version 10. (#13220)
- Add per-room rate limiting for room joins. For each room, Synapse now monitors the rate of join events in that room, and throttles additional joins if that rate grows too large. (#13253, #13254, #13255, #13276)
- Support Implicit TLS (TLS without using a STARTTLS upgrade, typically on port 465) for sending emails, enabled by the new option
force_tls
. Contributed by Jan Schär. (#13317)
- Fix a bug introduced in Synapse 1.15.0 where adding a user through the Synapse Admin API with a phone number would fail if the
enable_email_notifs
andemail_notifs_for_new_users
options were enabled. Contributed by @thomasweston12. (#13263) - Fix a bug introduced in Synapse 1.40.0 where a user invited to a restricted room would be briefly unable to join. (#13270)
- Fix a long-standing bug where, in rare instances, Synapse could store the incorrect state for a room after a state resolution. (#13278)
- Fix a bug introduced in v1.18.0 where the
synapse_pushers
metric would overcount pushers when they are replaced. (#13296) - Disable autocorrection and autocapitalisation on the username text field shown during registration when using SSO. (#13350)
- Update locked version of
frozendict
to 2.3.3, which has fixes for memory leaks affecting/sync
. (#13284, #13352)
- Provide an example of using the Admin API. Contributed by @jejo86. (#13231)
- Move the documentation for how URL previews work to the URL preview module. (#13233, #13261)
- Add another
contrib
script to help set up worker processes. Contributed by @villepeh. (#13271) - Document that certain config options were added or changed in Synapse 1.62. Contributed by @behrmann. (#13314)
- Document the new
rc_invites.per_issuer
throttling option added in Synapse 1.63. (#13333) - Mention that BuildKit is needed when building Docker images for tests. (#13338)
- Improve Caddy reverse proxy documentation. (#13344)
- Drop tables that were formerly used for groups/communities. (#12967)
- Drop support for delegating email verification to an external server. (#13192)
- Drop support for calling
/_matrix/client/v3/account/3pid/bind
without anid_access_token
, which was not permitted by the spec. Contributed by @Vetchu. (#13239) - Stop building
.deb
packages for Ubuntu 21.10 (Impish Indri), which has reached end of life. (#13326)
- Use lower transaction isolation level when purging rooms to avoid serialization errors. Contributed by Nick @ Beeper. (#12942)
- Remove code which incorrectly attempted to reconcile state with remote servers when processing incoming events. (#12943)
- Make the AS login method call
Auth.get_user_by_req
for checking the AS token. (#13094) - Always use a version of canonicaljson that supports the C implementation of frozendict. (#13172)
- Add prometheus counters for ephemeral events and to device messages pushed to app services. Contributed by Brad @ Beeper. (#13175)
- Refactor receipts servlet logic to avoid duplicated code. (#13198)
- Preparation for database schema simplifications: populate
state_key
andrejection_reason
for existing rows in theevents
table. (#13215) - Remove unused database table
event_reference_hashes
. (#13218) - Further reduce queries used sending events when creating new rooms. Contributed by Nick @ Beeper (@fizzadar). (#13224)
- Call the v2 identity service
/3pid/unbind
endpoint, rather than v1. Contributed by @Vetchu. (#13240) - Use an asynchronous cache wrapper for the get event cache. Contributed by Nick @ Beeper (@fizzadar). (#13242, #13308)
- Optimise federation sender and appservice pusher event stream processing queries. Contributed by Nick @ Beeper (@fizzadar). (#13251)
- Log the stack when waiting for an entire room to be un-partial stated. (#13257)
- Fix spurious warning when fetching state after a missing prev event. (#13258)
- Clean-up tests for notifications. (#13260)
- Do not fail build if complement with workers fails. (#13266)
- Don't pull out state in
compute_event_context
for unconflicted state. (#13267, #13274) - Reduce the rebuild time for the complement-synapse docker image. (#13279)
- Don't pull out the full state when creating an event. (#13281, #13307)
- Upgrade from Poetry 1.1.12 to 1.1.14, to fix bugs when locking packages. (#13285)
- Make
DictionaryCache
expire full entries if they haven't been queried in a while, even if specific keys have been queried recently. (#13292) - Use
HTTPStatus
constants in place of literals in tests. (#13297) - Improve performance of query
_get_subset_users_in_room_with_profiles
. (#13299) - Up batch size of
bulk_get_push_rules
and_get_joined_profiles_from_event_ids
. (#13300) - Remove unnecessary
json.dumps
from tests. (#13303) - Reduce memory usage of sending dummy events. (#13310)
- Prevent formatting changes of #3679 from appearing in
git blame
. (#13311) - Change
get_users_in_room
andget_rooms_for_user
caches to enable pruning of old entries. (#13313) - Validate federation destinations and log an error if a destination is invalid. (#13318)
- Fix
FederationClient.get_pdu()
returning events from the cache asoutliers
instead of original events we saw over federation. (#13320) - Reduce memory usage of state caches. (#13323)
- Reduce the amount of state we store in the
state_cache
. (#13324) - Add missing type hints to open tracing module. (#13328, #13345, #13362)
- Remove old base slaved store and de-duplicate cache ID generators. Contributed by Nick @ Beeper (@fizzadar). (#13329, #13349)
- When reporting metrics is enabled, use ~8x less data to describe DB transaction metrics. (#13342)
- Faster room joins: skip soft fail checks while Synapse only has partial room state, since the current membership of event senders may not be accurately known. (#13354)
- Fix a bug introduced in Synapse 1.63.0 where push actions were incorrectly calculated for appservice users. This caused performance issues on servers with large numbers of appservices. (#13332)
- Clarify that homeserver server names are included in the reported data when the
report_stats
config option is enabled. (#13321)
- Add a rate limit for local users sending invites. (#13125)
- Implement MSC3827: Filtering of
/publicRooms
by room type. (#13031) - Improve validation logic in the account data REST endpoints. (#13148)
- Fix a long-standing bug where application services were not able to join remote federated rooms without a profile. (#13131)
- Fix a long-standing bug where
_get_state_map_for_room
might raise errors when third party event rules callbacks are present. (#13174) - Fix a long-standing bug where the
synapse_port_db
script could fail to copy rows with negative row ids. (#13226) - Fix a bug introduced in 1.54.0 where appservices would not receive room-less EDUs, like presence, when both MSC2409 and MSC3202 are enabled. (#13236)
- Fix a bug introduced in 1.62.0 where rows were not deleted from
event_push_actions
table on large servers. (#13194) - Fix a bug introduced in 1.62.0 where notification counts would get stuck after a highlighted message. (#13223)
- Fix exception when using experimental MSC3030
/timestamp_to_event
endpoint to look for remote federated imported events before room creation. (#13197) - Fix MSC3202-enabled appservices not receiving to-device messages, preventing messages from being decrypted. (#13235)
- Bump the version of
lxml
in matrix.org Docker images Debian packages from 4.8.0 to 4.9.1. (#13207)
- Add an explanation of the
--report-stats
argument to the docs. (#13029) - Add a helpful example bash script to the contrib directory for creating multiple worker configuration files of the same type. Contributed by @villepeh. (#13032)
- Add missing links to config options. (#13166)
- Add documentation for homeserver usage statistics collection. (#13086)
- Add documentation for the existing
databases
option in the homeserver configuration manual. (#13212) - Clean up references to sample configuration and redirect users to the configuration manual instead. (#13077, #13139)
- Document how the Synapse team does reviews. (#13132)
- Fix wrong section header for
allow_public_rooms_over_federation
in the homeserver config documentation. (#13116)
- Remove obsolete and for 8 years unused
RoomEventsStoreTestCase
. Contributed by @arkamar. (#13200)
- Add type annotations to
synapse.logging
,tests.server
andtests.utils
. (#13028, #13103, #13159, #13136) - Enforce type annotations for
tests.test_server
. (#13135) - Support temporary experimental return values for spam checker module callbacks. (#13044)
- Add support to
complement.sh
for skipping the docker build. (#13143, #13158) - Add support to
complement.sh
for setting the log level using theSYNAPSE_TEST_LOG_LEVEL
environment variable. (#13152) - Enable Complement testing in the 'Twisted Trunk' CI runs. (#13079, #13157)
- Improve startup times in Complement test runs against workers, particularly in CPU-constrained environments. (#13127)
- Update config used by Complement to allow device name lookup over federation. (#13167)
- Faster room joins: handle race between persisting an event and un-partial stating a room. (#13100)
- Faster room joins: fix race in recalculation of current room state. (#13151)
- Faster room joins: skip waiting for full state when processing incoming events over federation. (#13144)
- Raise a
DependencyError
on missing dependencies instead of aConfigError
. (#13113) - Avoid stripping line breaks from SQL sent to the database. (#13129)
- Apply ratelimiting earlier in processing of
/send
requests. (#13134) - Improve exception handling when processing events received over federation. (#13145)
- Check that
auto_vacuum
is disabled when porting a SQLite database to Postgres, asVACUUM
s must not be performed between runs of the script. (#13195) - Reduce DB usage of
/sync
when a large number of unread messages have recently been sent in a room. (#13119, #13153) - Reduce memory consumption when processing incoming events in large rooms. (#13078, #13222)
- Reduce number of queries used to get profile information. Contributed by Nick @ Beeper (@fizzadar). (#13209)
- Reduce number of events queried during room creation. Contributed by Nick @ Beeper (@fizzadar). (#13210)
- More aggressively rotate push actions. (#13211)
- Add
max_line_length
setting for Python files to the.editorconfig
. Contributed by @sumnerevans @ Beeper. (#13228)
No significant changes since 1.62.0rc3.
Authors of spam-checker plugins should consult the upgrade notes to learn about the enriched signatures for spam checker callbacks, which are supported with this release of Synapse.
The following issue is fixed in 1.62.0.
-
GHSA-jhjh-776m-4765 / CVE-2022-31152
Synapse instances prior to 1.62.0 did not implement the Matrix event authorization rules correctly. An attacker could craft events which would be accepted by Synapse but not a spec-conformant server, potentially causing divergence in the room state between servers.
Homeservers with federation disabled via the
federation_domain_whitelist
config option are unaffected.Administrators of homeservers with federation enabled are advised to upgrade to v1.62.0 or higher.
- Update the version of the ldap3 plugin included in the
matrixdotorg/synapse
DockerHub images and the Debian packages hosted onpackages.matrix.org
to 0.2.1. This fixes a bug with usernames containing uppercase characters. (#13156) - Fix a bug introduced in Synapse 1.62.0rc1 affecting unread counts for users on small servers. (#13168)
- Fix unread counts for users on large servers. Introduced in v1.62.0rc1. (#13140)
- Fix DB performance when deleting old push notifications. Introduced in v1.62.0rc1. (#13141)
- Port the spam-checker API callbacks to a new, richer API. This is part of an ongoing change to let spam-checker modules inform users of the reason their event or operation is rejected. (#12857, #13047)
- Allow server admins to customise the response of the
/.well-known/matrix/client
endpoint. (#13035) - Add metrics measuring the CPU and DB time spent in state resolution. (#13036)
- Speed up fetching of device list changes in
/sync
and/keys/changes
. (#13045, #13098) - Improve URL previews for sites which only provide Twitter Card metadata, e.g. LWN.net. (#13056)
- Update MSC3786 implementation to check
state_key
. (#12939) - Fix a bug introduced in Synapse 1.58 where Synapse would not report full version information when installed from a git checkout. This is a best-effort affair and not guaranteed to be stable. (#12973)
- Fix a bug introduced in Synapse 1.60 where Synapse would fail to start if the
sqlite3
module was not available. (#12979) - Fix a bug where non-standard information was required when requesting the
/hierarchy
API over federation. Introduced in Synapse v1.41.0. (#12991) - Fix a long-standing bug which meant that rate limiting was not restrictive enough in some cases. (#13018)
- Fix a bug introduced in Synapse 1.58 where profile requests for a malformed user ID would ccause an internal error. Synapse now returns 400 Bad Request in this situation. (#13041)
- Fix some inconsistencies in the event authentication code. (#13087, #13088)
- Fix a long-standing bug where room directory requests would cause an internal server error if given a malformed room alias. (#13106)
- Add documentation for how to configure Synapse with Workers using Docker Compose. Includes example worker config and docker-compose.yaml. Contributed by @Thumbscrew. (#12737)
- Ensure the Poetry cheat sheet is available in the online documentation. (#13022)
- Mention removed community/group worker endpoints in upgrade.md. Contributed by @olmari. (#13023)
- Add instructions for running Complement with
gotestfmt
-formatted output locally. (#13073) - Update OpenTracing docs to reference the configuration manual rather than the configuration file. (#13076)
- Update information on downstream Debian packages. (#13095)
- Remove documentation for the Delete Group Admin API which no longer exists. (#13112)
- Remove the unspecced
DELETE /directory/list/room/{roomId}
endpoint, which hid rooms from the public room directory. Instead,PUT
to the same URL with a visibility of"private"
. (#13123)
- Add tests for cancellation of
GET /rooms/$room_id/members
andGET /rooms/$room_id/state
requests. (#12674) - Report login failures due to unknown third party identifiers in the same way as failures due to invalid passwords. This prevents an attacker from using the error response to determine if the identifier exists. Contributed by Daniel Aloni. (#12738)
- Merge the Complement testing Docker images into a single, multi-purpose image. (#12881, #13075)
- Simplify the database schema for
event_edges
. (#12893) - Clean up the test code for client disconnection. (#12929)
- Remove code generating comments in configuration. (#12941)
- Add
Cross-Origin-Resource-Policy: cross-origin
header to content repository's thumbnail and download endpoints. (#12944) - Replace noop background updates with
DELETE
delta. (#12954, #13050) - Use lower isolation level when inserting read receipts to avoid serialization errors. Contributed by Nick @ Beeper. (#12957)
- Reduce the amount of state we pull from the DB. (#12963)
- Enable testing against PostgreSQL databases in Complement CI. (#12965, #13034)
- Fix an inaccurate comment. (#12969)
- Remove the
delete_device
method and always calldelete_devices
. (#12970) - Use a GitHub form for issues rather than a hard-to-read, easy-to-ignore template. (#12982)
- Move MSC3715 behind an experimental config flag. (#12984)
- Add type hints to tests. (#12985, #13099)
- Refactor macaroon tokens generation and move the unsubscribe link in notification emails to
/_synapse/client/unsubscribe
. (#12986) - Fix documentation for running complement tests. (#12990)
- Faster joins: add issue links to the TODO comments in the code. (#13004)
- Reduce DB usage of
/sync
when a large number of unread messages have recently been sent in a room. (#13005, #13096, #13118) - Replaced usage of PyJWT with methods from Authlib in
org.matrix.login.jwt
. Contributed by Hannes Lerchl. (#13011) - Modernize the
contrib/graph/
scripts. (#13013) - Remove redundant
room_version
parameters from event auth functions. (#13017) - Decouple
synapse.api.auth_blocking.AuthBlocking
fromsynapse.api.auth.Auth
. (#13021) - Add type annotations to
synapse.storage.databases.main.devices
. (#13025) - Set default
sync_response_cache_duration
to two minutes. (#13042) - Rename CI test runs. (#13046)
- Increase timeout of complement CI test runs. (#13048)
- Refactor entry points so that they all have a
main
function. (#13052) - Refactor the Dockerfile-workers configuration script to use Jinja2 templates in Synapse workers' Supervisord blocks. (#13054)
- Add headers to individual options in config documentation to allow for linking. (#13055)
- Make Complement CI logs easier to read. (#13057, #13058, #13069)
- Don't instantiate modules with keyword arguments. (#13060)
- Fix type checking errors against Twisted trunk. (#13061)
- Allow MSC3030
timestamp_to_event
calls from anyone on world-readable rooms. (#13062) - Add a CI job to check that schema deltas are in the correct folder. (#13063)
- Avoid rechecking event auth rules which are independent of room state. (#13065)
- Reduce the duplication of code that invokes the rate limiter. (#13070)
- Add a Subject Alternative Name to the certificate generated for Complement tests. (#13071)
- Add more tests for room upgrades. (#13074)
- Pin dependencies maintained by matrix.org to semantic version bounds. (#13082)
- Correctly report prometheus DB stats for
get_earliest_token_for_stats
. (#13085) - Fix a long-standing bug where a finished logging context would be re-started when Synapse failed to persist an event from federation. (#13089)
- Simplify the alias deletion logic as an application service. (#13093)
- Add type annotations to
tests.test_server
. (#13124)
This patch release fixes a security issue regarding URL previews, affecting all prior versions of Synapse. Server administrators are encouraged to update Synapse as soon as possible. We are not aware of these vulnerabilities being exploited in the wild.
Server administrators who are unable to update Synapse may use the workarounds described in the linked GitHub Security Advisory below.
The following issue is fixed in 1.61.1.
-
GHSA-22p3-qrh9-cx32 / CVE-2022-31052
Synapse instances with the
url_preview_enabled
homeserver config option set totrue
are affected. URL previews of some web pages can lead to unbounded recursion, causing the request to either fail, or in some cases crash the running Synapse process.Requesting URL previews requires authentication. Nevertheless, it is possible to exploit this maliciously, either by malicious users on the homeserver, or by remote users sending URLs that a local user's client may automatically request a URL preview for.
Homeservers with the
url_preview_enabled
configuration option set tofalse
(the default) are unaffected. Instances with theenable_media_repo
configuration option set tofalse
are also unaffected, as this also disables URL preview functionality.Fixed by fa1308061802ac7b7d20e954ba7372c5ac292333.
This release removes support for the non-standard feature known both as 'groups' and as 'communities', which have been superseded by Spaces.
See the upgrade notes for more details.
- Mention removed community/group worker endpoints in the upgrade notes. Contributed by @olmari. (#13023)
- Add new
media_retention
options to the homeserver config for routinely cleaning up non-recently accessed media. (#12732, #12972, #12977) - Experimental support for MSC3772: Push rule for mutually related events. (#12740, #12859)
- Update to the
check_event_for_spam
module callback: Deprecate the current callback signature, replace it with a new signature that is both less ambiguous (replacing booleans with explicit allow/block) and more powerful (ability to return explicit error codes). (#12808) - Add storage and module API methods to get monthly active users (and their corresponding appservices) within an optionally specified time range. (#12838, #12917)
- Support the new error code
ORG.MATRIX.MSC3823.USER_ACCOUNT_SUSPENDED
from MSC3823. (#12845, #12923) - Add a configurable background job to delete stale devices. (#12855)
- Improve URL previews for pages with empty elements. (#12951)
- Allow updating a user's password using the admin API without logging out their devices. Contributed by @jcgruenhage. (#12952)
- Always send an
access_token
in/thirdparty/
requests to appservices, as required by the Application Service API specification. (#12746) - Implement MSC3816: sending the root event in a thread should count as having 'participated' in it. (#12766)
- Delete events from the
federation_inbound_events_staging
table when a room is purged through the admin API. (#12784) - Fix a bug where we did not correctly handle invalid device list updates over federation. Contributed by Carl Bordum Hansen. (#12829)
- Fix a bug which allowed multiple async operations to access database locks concurrently. Contributed by @sumnerevans @ Beeper. (#12832)
- Fix an issue introduced in Synapse 0.34 where the
/notifications
endpoint would only return notifications if a user registered at least one pusher. Contributed by Famedly. (#12840) - Fix a bug where servers using a Postgres database would fail to backfill from an insertion event when MSC2716 is enabled (
experimental_features.msc2716_enabled
). (#12843) - Fix MSC3787 rooms being omitted from room directory, room summary and space hierarchy responses. (#12858)
- Fix a bug introduced in Synapse 1.54.0 which could sometimes cause exceptions when handling federated traffic. (#12877)
- Fix a bug introduced in Synapse 1.59.0 which caused room deletion to fail with a foreign key violation error. (#12889)
- Fix a long-standing bug which caused the
/messages
endpoint to return an incorrectend
attribute when there were no more events. Contributed by @Vetchu. (#12903) - Fix a bug introduced in Synapse 1.58.0 where
/sync
would fail if the most recent event in a room was a redaction of an event that has since been purged. (#12905) - Fix a potential memory leak when generating thumbnails. (#12932)
- Fix a long-standing bug where a URL preview would break if the image failed to download. (#12950)
- Fix typographical errors in documentation. (#12863)
- Fix documentation incorrectly stating the
sendToDevice
endpoint can be directed at generic workers. Contributed by Nick @ Beeper. (#12867)
- Remove support for the non-standard groups/communities feature from Synapse. (#12553, #12558, #12563, #12895, #12897, #12899, #12900, #12936, #12966)
- Remove contributed
kick_users.py
script. This is broken under Python 3, and is not added to the environment whenpip install
ing Synapse. (#12908) - Remove
contrib/jitsimeetbridge
. This was an unused experiment that hasn't been meaningfully changed since 2014. (#12909) - Remove unused
contrib/experiements/cursesio.py
script, which fails to run under Python 3. (#12910) - Remove unused
contrib/experiements/test_messaging.py
script. This fails to run on Python 3. (#12911)
- Test Synapse against Complement with workers. (#12810, #12933)
- Reduce the amount of state we pull from the DB. (#12811, #12964)
- Try other homeservers when re-syncing state for rooms with partial state. (#12812)
- Resume state re-syncing for rooms with partial state after a Synapse restart. (#12813)
- Remove Mutual Rooms' (MSC2666) endpoint dependency on the User Directory. (#12836)
- Experimental: expand
check_event_for_spam
with ability to return additional fields. This enables spam-checker implementations to experiment with mechanisms to give users more information about why they are blocked and whether any action is needed from them to be unblocked. (#12846) - Remove
dont_notify
from the.m.rule.room.server_acl
rule. (#12849) - Remove the unstable
/hierarchy
endpoint from MSC2946. (#12851) - Pull out less state when handling gaps in room DAG. (#12852, #12904)
- Clean-up the push rules datastore. (#12856)
- Correct a type annotation in the URL preview source code. (#12860)
- Update
pyjwt
dependency to 2.4.0. (#12865) - Enable the
/account/whoami
endpoint on synapse worker processes. Contributed by Nick @ Beeper. (#12866) - Enable the
batch_send
endpoint on synapse worker processes. Contributed by Nick @ Beeper. (#12868) - Don't generate empty AS transactions when the AS is flagged as down. Contributed by Nick @ Beeper. (#12869)
- Fix up the variable
state_store
naming. (#12871) - Faster room joins: when querying the current state of the room, wait for state to be populated. (#12872)
- Avoid running queries which will never result in deletions. (#12879)
- Use constants for EDU types. (#12884)
- Reduce database load of
/sync
when presence is enabled. (#12885) - Refactor
have_seen_events
to reduce memory consumed when processing federation traffic. (#12886) - Refactor receipt linearization code. (#12888)
- Add type annotations to
synapse.logging.opentracing
. (#12894) - Remove PyNaCl occurrences directly used in Synapse code. (#12902)
- Bump types-jsonschema from 4.4.1 to 4.4.6. (#12912)
- Rename storage classes. (#12913)
- Preparation for database schema simplifications: stop reading from
event_edges.room_id
. (#12914) - Check if we are in a virtual environment before overriding the
PYTHONPATH
environment variable in the demo script. (#12916) - Improve the logging when signature checks on events fail. (#12925)
This release of Synapse adds a unique index to the state_group_edges
table, in
order to prevent accidentally introducing duplicate information (for example,
because a database backup was restored multiple times). If your Synapse database
already has duplicate rows in this table, this could fail with an error and
require manual remediation.
Additionally, the signature of the check_event_for_spam
module callback has changed.
The previous signature has been deprecated and remains working for now. Module authors
should update their modules to use the new signature where possible.
See the upgrade notes for more details.
- Fix a bug introduced in Synapse 1.60.0rc1 that would break some imports from
synapse.module_api
. (#12918)
- Add an option allowing users to use their password to reauthenticate for privileged actions even though password login is disabled. (#12883)
- Explicitly close
ijson
coroutines once we are done with them, instead of leaving the garbage collector to close them. (#12875)
- Improve URL previews by not including the content of media tags in the generated description. (#12887)
- Measure the time taken in spam-checking callbacks and expose those measurements as metrics. (#12513)
- Add a
default_power_level_content_override
config option to set default room power levels per room preset. (#12618) - Add support for MSC3787: Allowing knocks to restricted rooms. (#12623)
- Send
USER_IP
commands on a different Redis channel, in order to reduce traffic to workers that do not process these commands. (#12672, #12809) - Synapse will now reload cache config when it receives a SIGHUP signal. (#12673)
- Add a config options to allow for auto-tuning of caches. (#12701)
- Update MSC2716 implementation to process marker events from the current state to avoid markers being lost in timeline gaps for federated servers which would cause the imported history to be undiscovered. (#12718)
- Add a
drop_federated_event
callback toSpamChecker
to disregard inbound federated events before they take up much processing power, in an emergency. (#12744) - Implement MSC3818: Copy room type on upgrade. (#12786, #12792)
- Update to the
check_event_for_spam
module callback. Deprecate the current callback signature, replace it with a new signature that is both less ambiguous (replacing booleans with explicit allow/block) and more powerful (ability to return explicit error codes). (#12808)
- Fix a bug introduced in Synapse 1.7.0 that would prevent events from being sent to clients if there's a retention policy in the room when the support for retention policies is disabled. (#12611)
- Fix a bug introduced in Synapse 1.57.0 where
/messages
would throw a 500 error when querying for a non-existent room. (#12683) - Add a unique index to
state_group_edges
to prevent duplicates being accidentally introduced and the consequential impact to performance. (#12687) - Fix a long-standing bug where an empty room would be created when a user with an insufficient power level tried to upgrade a room. (#12696)
- Fix a bug introduced in Synapse 1.30.0 where empty rooms could be automatically created if a monthly active users limit is set. (#12713)
- Fix push to dismiss notifications when read on another client. Contributed by @SpiritCroc @ Beeper. (#12721)
- Fix poor database performance when reading the cache invalidation stream for large servers with lots of workers. (#12747)
- Fix a long-standing bug where the user directory background process would fail to make forward progress if a user included a null codepoint in their display name or avatar. (#12762)
- Delete events from the
federation_inbound_events_staging
table when a room is purged through the admin API. (#12770) - Give a meaningful error message when a client tries to create a room with an invalid alias localpart. (#12779)
- Fix a bug introduced in 1.43.0 where a file (
providers.json
) was never closed. Contributed by @arkamar. (#12794) - Fix a long-standing bug where finished log contexts would be re-started when failing to contact remote homeservers. (#12803)
- Fix a bug, introduced in Synapse 1.21.0, that led to media thumbnails being unusable before the index has been added in the background. (#12823)
- Fix the docker file after a dependency update. (#12853)
- Fix a typo in the Media Admin API documentation. (#12715)
- Update the OpenID Connect example for Keycloak to be compatible with newer versions of Keycloak. Contributed by @nhh. (#12727)
- Fix typo in server listener documentation. (#12742)
- Link to the configuration manual from the welcome page of the documentation. (#12748)
- Fix typo in
run_background_tasks_on
option name in configuration manual documentation. (#12749) - Add information regarding the
rc_invites
ratelimiting option to the configuration docs. (#12759) - Add documentation for cancellation of request processing. (#12761)
- Recommend using docker to run tests against postgres. (#12765)
- Add missing user directory endpoint from the generic worker documentation. Contributed by @olmari. (#12773)
- Add additional info to documentation of config option
cache_autotuning
. (#12776) - Update configuration manual documentation to document size-related suffixes. (#12777)
- Fix invalid YAML syntax in the example documentation for the
url_preview_accept_language
config option. (#12785)
- Require a body in POST requests to
/rooms/{roomId}/receipt/{receiptType}/{eventId}
, as required by the Matrix specification. This breaks compatibility with Element Android 1.2.0 and earlier: users of those clients will be unable to send read receipts. (#12709)
- Improve event caching mechanism to avoid having multiple copies of an event in memory at a time. (#10533)
- Preparation for faster-room-join work: return subsets of room state which we already have, immediately. (#12498)
- Add
@cancellable
decorator, for use on endpoint methods that can be cancelled when clients disconnect. (#12586, #12588, #12630, #12694, #12698, #12699, #12700, #12705) - Enable cancellation of
GET /rooms/$room_id/members
,GET /rooms/$room_id/state
andGET /rooms/$room_id/state/$event_type/*
requests. (#12708) - Improve documentation of the
synapse.push
module. (#12676) - Refactor functions to on
PushRuleEvaluatorForEvent
. (#12677) - Preparation for database schema simplifications: stop writing to
event_reference_hashes
. (#12679) - Remove code which updates unused database column
application_services_state.last_txn
. (#12680) - Refactor
EventContext
class. (#12689) - Remove an unneeded class in the push code. (#12691)
- Consolidate parsing of relation information from events. (#12693)
- Convert namespace class
Codes
into a string enum. (#12703) - Optimize private read receipt filtering. (#12711)
- Drop the logging level of status messages for the URL preview cache expiry job from INFO to DEBUG. (#12720)
- Downgrade some OIDC errors to warnings in the logs, to reduce the noise of Sentry reports. (#12723)
- Update configs used by Complement to allow more invites/3PID validations during tests. (#12731)
- Tweak the mypy plugin so that
@cached
can accepton_invalidate=None
. (#12769) - Move methods that call
add_push_rule
to thePushRuleStore
class. (#12772) - Make handling of federation Authorization header (more) compliant with RFC7230. (#12774)
- Refactor
resolve_state_groups_for_events
to not pull out full state when no state resolution happens. (#12775) - Do not keep going if there are 5 back-to-back background update failures. (#12781)
- Fix federation when using the demo scripts. (#12783)
- The
hash_password
script now fails when it is called without specifying a config file. Contributed by @jae1911. (#12789) - Improve and fix type hints. (#12567, #12477, #12717, #12753, #12695, #12734, #12716, #12726, #12790, #12833)
- Update EventContext
get_current_event_ids
andget_prev_event_ids
to accept state filters and update calls where possible. (#12791) - Remove Caddy from the Synapse workers image used in Complement. (#12818)
- Add Complement's shared registration secret to the Complement worker image. This fixes tests that depend on it. (#12819)
- Support registering Application Services when running with workers under Complement. (#12826)
- Disable 'faster room join' Complement tests when testing against Synapse with workers. (#12842)
This release fixes a long-standing issue which could prevent Synapse's user directory for updating properly.
- Fix a long-standing bug where the user directory background process would fail to make forward progress if a user included a null codepoint in their display name or avatar. Contributed by Nick @ Beeper. (#12762)
Synapse 1.59 makes several changes that server administrators should be aware of:
- Device name lookup over federation is now disabled by default. (#12616)
- The
synapse.app.appservice
andsynapse.app.user_dir
worker application types are now deprecated. (#12452, #12654)
See the upgrade notes for more details.
Additionally, this release removes the non-standard m.login.jwt
login type from Synapse. It can be replaced with org.matrix.login.jwt
for identical behaviour. This is only used if jwt_config.enabled
is set to true
in the configuration. (#12597)
- Fix DB performance regression introduced in Synapse 1.59.0rc2. (#12745)
Note: this release candidate includes a performance regression which can cause database disruption. Other release candidates in the v1.59.0 series are not affected, and a fix will be included in the v1.59.0 final release.
- Fix a bug introduced in Synapse 1.58.0 where
/sync
would fail if the most recent event in a room was rejected. (#12729)
- Support MSC3266 room summaries over federation. (#11507)
- Implement changes to MSC2285 (hidden read receipts). Contributed by @SimonBrandner. (#12168, #12635, #12636, #12670)
- Extend the module API to allow modules to change actions for existing push rules of local users. (#12406)
- Add the
notify_appservices_from_worker
configuration option (supersedingnotify_appservices
) to allow a generic worker to be designated as the worker to send traffic to Application Services. (#12452) - Add the
update_user_directory_from_worker
configuration option (supersedingupdate_user_directory
) to allow a generic worker to be designated as the worker to update the user directory. (#12654) - Add new
enable_registration_token_3pid_bypass
configuration option to allow registrations via token as an alternative to verifying a 3pid. (#12526) - Implement MSC3786: Add a default push rule to ignore
m.room.server_acl
events. (#12601) - Add new
mau_appservice_trial_days
configuration option to specify a different trial period for users registered via an appservice. (#12619)
- Fix a bug introduced in Synapse 1.48.0 where the latest thread reply provided failed to include the proper bundled aggregations. (#12273)
- Fix a bug introduced in Synapse 1.22.0 where attempting to send a large amount of read receipts to an application service all at once would result in duplicate content and abnormally high memory usage. Contributed by Brad & Nick @ Beeper. (#12544)
- Fix a bug introduced in Synapse 1.57.0 which could cause
Failed to calculate hosts in room
errors to be logged for outbound federation. (#12570) - Fix a long-standing bug where status codes would almost always get logged as
200!
, irrespective of the actual status code, when clients disconnect before a request has finished processing. (#12580) - Fix race when persisting an event and deleting a room that could lead to outbound federation breaking. (#12594)
- Fix a bug introduced in Synapse 1.53.0 where bundled aggregations for annotations/edits were incorrectly calculated. (#12633)
- Fix a long-standing bug where rooms containing power levels with string values could not be upgraded. (#12657)
- Prevent memory leak from reoccurring when presence is disabled. (#12656)
- Explicitly opt-in to using BuildKit-specific features in the Dockerfile. This fixes issues with building images in some GitLab CI environments. (#12541)
- Update the "Build docker images" GitHub Actions workflow to use
docker/metadata-action
to generate docker image tags, instead of a custom shell script. Contributed by @henryclw. (#12573)
- Update SQL statements and replace use of old table
user_stats_historical
in docs for Synapse Admins. (#12536) - Add missing linebreak to
pipx
install instructions. (#12579) - Add information about the TCP replication module to docs. (#12621)
- Fixes to the formatting of
README.rst
. (#12627) - Fix docs on how to run specific Complement tests using the
complement.sh
test runner. (#12664)
- Remove unstable identifiers from MSC3069. (#12596)
- Remove the unspecified
m.login.jwt
login type and the unstableuk.half-shot.msc2778.login.application_service
from MSC2778. (#12597) - Synapse now requires at least Python 3.7.1 (up from 3.7.0), for compatibility with the latest Twisted trunk. (#12613)
- Use supervisord to supervise Postgres and Caddy in the Complement image to reduce restart time. (#12480)
- Immediately retry any requests that have backed off when a server comes back online. (#12500)
- Use
make_awaitable
instead ofdefer.succeed
for return values of mocks in tests. (#12505) - Consistently check if an object is a
frozendict
. (#12564) - Protect module callbacks with read semantics against cancellation. (#12568)
- Improve comments and error messages around access tokens. (#12577)
- Improve docstrings for the receipts store. (#12581)
- Use constants for read-receipts in tests. (#12582)
- Log status code of cancelled requests as 499 and avoid logging stack traces for them. (#12587, #12663)
- Remove special-case for
twisted
logger from default log config. (#12589) - Use
getClientAddress
instead of the deprecatedgetClientIP
. (#12599) - Add link to documentation in Grafana Dashboard. (#12602)
- Reduce log spam when running multiple event persisters. (#12610)
- Add extra debug logging to federation sender. (#12614)
- Prevent remote homeservers from requesting local user device names by default. (#12616)
- Add a consistency check on events which we read from the database. (#12620)
- Remove use of the
constantly
library and switch to enums forEventRedactBehaviour
. Contributed by @andrewdoh. (#12624) - Remove unused code related to receipts. (#12632)
- Minor improvements to the scripts for running Synapse in worker mode under Complement. (#12637)
- Move
pympler
back in to theall
extras. (#12652) - Fix spelling of
M_UNRECOGNIZED
in comments. (#12665) - Release script: confirm the commit to be tagged before tagging. (#12556)
- Fix a typo in the announcement text generated by the Synapse release development script. (#12612)
- Fix scripts-dev to pass typechecking. (#12356)
- Add some type hints to datastore. (#12485)
- Remove unused
# type: ignore
s. (#12531) - Allow unused
# type: ignore
comments in bleeding edge CI jobs. (#12576) - Remove redundant lines of config from
mypy.ini
. (#12608) - Update to mypy 0.950. (#12650)
- Use
Concatenate
to better annotate_do_execute
. (#12666) - Use
ParamSpec
to refine type hints. (#12667) - Fix mypy against latest pillow stubs. (#12671)
This patch release includes a fix to the Debian packages, installing the
systemd
and cache_memory
extra package groups, which were incorrectly
omitted in v1.58.0. This primarily prevented Synapse from starting
when the systemd.journal.JournalHandler
log handler was configured.
See #12631 for further information.
Otherwise, no significant changes since 1.58.0.
As of this release, the groups/communities feature in Synapse is now disabled by default. See #11584 for details. As mentioned in the upgrade notes, this feature will be removed in Synapse 1.61.
No significant changes since 1.58.0rc2.
This release candidate fixes bugs related to Synapse 1.58.0rc1's logic for handling device list updates.
- Fix a bug introduced in Synapse 1.58.0rc1 where the main process could consume excessive amounts of CPU and memory while handling sentry logging failures. (#12554)
- Fix a bug introduced in Synapse 1.58.0rc1 where opentracing contexts were not correctly sent to whitelisted remote servers with device lists updates. (#12555)
- Reduce unnecessary work when handling remote device list updates. (#12557)
- Implement MSC3383 for including the destination in server-to-server authentication headers. Contributed by @Bubu and @jcgruenhage for Famedly. (#11398)
- Docker images and Debian packages from matrix.org now contain a locked set of Python dependencies, greatly improving build reproducibility. (Board, #11537)
- Enable processing of device list updates asynchronously. (#12365, #12465)
- Implement MSC2815 to allow room moderators to view redacted event content. Contributed by @tulir @ Beeper. (#12427)
- Build Debian packages for Ubuntu 22.04 "Jammy Jellyfish". (#12543)
- Prevent a sync request from removing a user's busy presence status. (#12213)
- Fix bug with incremental sync missing events when rejoining/backfilling. Contributed by Nick @ Beeper. (#12319)
- Fix a long-standing bug which incorrectly caused
GET /_matrix/client/v3/rooms/{roomId}/event/{eventId}
to return edited events rather than the original. (#12476) - Fix a bug introduced in Synapse 1.27.0 where the admin API for deleting forward extremities would always return a count of 1, no matter how many extremities were deleted. (#12496)
- Fix a long-standing bug where the image thumbnails embedded into email notifications were broken. (#12510)
- Fix a bug in the implementation of MSC3202 where Synapse would use the field name
device_unused_fallback_keys
, rather thandevice_unused_fallback_key_types
. (#12520) - Fix a bug introduced in Synapse 0.99.3 which could cause Synapse to consume large amounts of RAM when back-paginating in a large room. (#12522)
- Fix rendering of the documentation site when using the 'print' feature. (#12340)
- Add a manual documenting config file options. (#12368, #12527)
- Update documentation to reflect that both the
run_background_tasks_on
option and the options for moving stream writers off of the main process are no longer experimental. (#12451) - Update worker documentation and replace old
federation_reader
withgeneric_worker
. (#12457) - Strongly recommend Poetry for development. (#12475)
- Add some example configurations for workers and update architectural diagram. (#12492)
- Fix a broken link in
README.rst
. (#12495) - Add HAProxy delegation example with CORS headers to docs. (#12501)
- Remove extraneous comma in User Admin API's device deletion section so that the example JSON is actually valid and works. Contributed by @olmari. (#12533)
- The groups/communities feature in Synapse is now disabled by default. (#12344)
- Remove unstable identifiers from MSC3440. (#12382)
- Preparation for faster-room-join work: start a background process to resynchronise the room state after a room join. (#12394)
- Preparation for faster-room-join work: Implement a tracking mechanism to allow functions to wait for full room state to arrive. (#12399)
- Remove an unstable identifier from MSC3083. (#12395)
- Run CI in the locked Poetry environment, and remove corresponding
tox
jobs. (#12425, #12434, #12438, #12441, #12449, #12478, #12514, #12472) - Change Mutual Rooms'
unstable_features
flag touk.half-shot.msc2666.mutual_rooms
which matches the current iteration of MSC2666. (#12445) - Fix typo in the release script help string. (#12450)
- Fix a minor typo in the Debian changelogs generated by the release script. (#12497)
- Reintroduce the list of targets to the linter script, to avoid linting unwanted local-only directories during development. (#12455)
- Limit length of
device_id
to less than 512 characters. (#12454) - Dockerfile-workers: reduce the amount we install in the image. (#12464)
- Dockerfile-workers: give the master its own log config. (#12466)
- complement-synapse-workers: factor out separate entry point script. (#12467)
- Back out experimental implementation of MSC2314. (#12474)
- Fix grammatical error in federation error response when the room version of a room is unknown. (#12483)
- Remove unnecessary configuration overrides in tests. (#12511)
- Refactor the relations code for clarity. (#12519)
- Add type hints so
docker
andstubs
directories passmypy --disallow-untyped-defs
. (#12528) - Update
delay_cancellation
to accept any awaitable, rather than justDeferred
s. (#12468) - Handle cancellation in
EventsWorkerStore._get_events_from_cache_or_db
. (#12529)
This is a patch release that only affects the Docker image. It is only of interest to administrators using the LDAP module to authenticate their users. If you have already upgraded to Synapse 1.57.0 without problem, then you have no need to upgrade to this patch release.
- Include version 0.2.0 of the Synapse LDAP Auth Provider module in the Docker image. This matches the version that was present in the Docker image for Synapse v1.56.0. (#12512)
This version includes a change to the way transaction IDs are managed for application services. If your deployment uses a dedicated worker for application service traffic, it must be stopped when the database is upgraded (which normally happens when the main process is upgraded), to ensure the change is made safely without any risk of reusing transaction IDs.
See the upgrade notes for more details.
No significant changes since 1.57.0rc1.
- Send device list changes to application services as specified by MSC3202, using unstable prefixes. The
msc3202_transaction_extensions
experimental homeserver config option must be enabled andorg.matrix.msc3202: true
must be present in the application service registration file for device list changes to be sent. The "left" field is currently always empty. (#11881) - Optimise fetching large quantities of missing room state over federation. (#12040)
- Offload the
update_client_ip
background job from the main process to the background worker, when using Redis-based replication. (#12251) - Move
update_client_ip
background job from the main process to the background worker. (#12252) - Add a module callback to react to new 3PID (email address, phone number) associations. (#12302)
- Add a configuration option to remove a specific set of rooms from sync responses. (#12310)
- Add a module callback to react to account data changes. (#12327)
- Allow setting user admin status using the module API. Contributed by Famedly. (#12341)
- Reduce overhead of restarting synchrotrons. (#12367, #12372)
- Update
/messages
to use historic pagination tokens if nofrom
query parameter is given. (#12370) - Add a module API for reading and writing global account data. (#12391)
- Support the stable
v1
endpoint for/relations
, per MSC2675. (#12403) - Include bundled aggregations in search results (MSC3666). (#12436)
- Fix a long-standing bug where updates to the server notices user profile (display name/avatar URL) in the configuration would not be applied to pre-existing rooms. Contributed by Jorge Florian. (#12115)
- Fix a long-standing bug where events from ignored users were still considered for bundled aggregations. (#12235, #12338)
- Fix non-member state events not resolving for historical events when used in MSC2716
/batch_send
state_events_at_start
. (#12329) - Fix a long-standing bug affecting URL previews that would generate a 500 response instead of a 403 if the previewed URL includes a port that isn't allowed by the relevant blacklist. (#12333)
- Default to
private
room visibility rather thanpublic
when a client does not specify one, according to spec. (#12350) - Fix a spec compliance issue where requests to the
/publicRooms
federation API would specifylimit
as a string. (#12364, #12410) - Fix a bug introduced in Synapse 1.49.0 which caused the
synapse_event_persisted_position
metric to have invalid values. (#12390)
- Bundle locked versions of dependencies into the Docker image. (#12385, #12439)
- Fix up healthcheck generation for workers docker image. (#12405)
- Clarify documentation for running SyTest against Synapse, including use of Postgres and worker mode. (#12271)
- Document the behaviour of
LoggingTransaction.call_after
andLoggingTransaction.call_on_exception
methods when transactions are retried. (#12315) - Update dead links in
check-newsfragment.sh
to point to the correct documentation URL. (#12331) - Upgrade the version of
mdbook
in CI to 0.4.17. (#12339) - Updates to the Room DAG concepts development document to clarify that we mark events as outliers because we don't have any state for them. (#12345)
- Update the link to Redis pub/sub documentation in the workers documentation. (#12369)
- Remove documentation for converting a legacy structured logging configuration to the new format. (#12392)
- Remove lingering unstable references to MSC2403 (knocking). (#12165)
- Avoid trying to calculate the state at outlier events. (#12191, #12316, #12330, #12332, #12409)
- Omit sending "offline" presence updates to application services after they are initially configured. (#12193)
- Switch to using a sequence to generate AS transaction IDs. Contributed by Nick @ Beeper. If running synapse with a dedicated appservice worker, this MUST be stopped before upgrading the main process and database. (#12209)
- Add missing type hints for storage. (#12267)
- Add missing type definitions for scripts in docker folder. Contributed by Jorge Florian. (#12280)
- Move MSC2654 support behind an experimental configuration flag. (#12295)
- Update docstrings to explain how to decipher live and historic pagination tokens. (#12317)
- Add ground work for speeding up device list updates for users in large numbers of rooms. (#12321)
- Fix typechecker problems exposed by signedjson 1.1.2. (#12326)
- Remove the
tox
packaging job: it will be redundant once #11537 lands. (#12334) - Ignore
.envrc
fordirenv
users. (#12335) - Remove the (broadly unused, dev-only) dockerfile for pg tests. (#12336)
- Remove redundant
get_success
calls in test code. (#12346) - Add type annotations for
tests/unittest.py
. (#12347) - Move single-use methods out of
TestCase
. (#12348) - Remove broken and unused development scripts. (#12349, #12351, #12355)
- Convert
Linearizer
tests frominlineCallbacks
to async. (#12353) - Update docstrings for
ReadWriteLock
tests. (#12354) - Refactor
Linearizer
, convert methods to async and use an async context manager. (#12357) - Fix a long-standing bug where
Linearizer
s could get stuck if a cancellation were to happen at the wrong time. (#12358) - Make
StreamToken.from_string
andRoomStreamToken.parse
propagate cancellations instead of replacing them withSynapseError
s. (#12366) - Add type hints to tests files. (#12371)
- Allow specifying the Postgres database's port when running unit tests with Postgres. (#12376)
- Remove temporary pin of signedjson<=1.1.1 that was added in Synapse 1.56.0. (#12379)
- Add opentracing spans to calls to external cache. (#12380)
- Lay groundwork for using
poetry
to manage Synapse's dependencies. (#12381, #12407, #12412, #12418) - Make missing
importlib_metadata
dependency explicit. (#12384, #12400) - Update type annotations for compatiblity with prometheus_client 0.14. (#12389)
- Remove support for the unstable identifiers specified in MSC3288. (#12398)
- Add missing type hints to configuration classes. (#12402)
- Add files used to build the Docker image used for complement testing into the Synapse repository. (#12404)
- Do not include groups in the sync response when disabled. (#12408)
- Improve type hints related to HTTP query parameters. (#12415)
- Stop maintaining a list of lint targets. (#12420)
- Make
synapse._scripts
pass type checks. (#12421, #12422) - Add some type hints to datastore. (#12423)
- Enable certificate checking during complement tests. (#12435)
- Explicitly specify the
tls
extra for Twisted dependency. (#12444)
Synapse will now refuse to start up if open registration is enabled, in order to help mitigate
abuse across the federation. If you would like
to provide registration to anyone, consider adding email,
recaptcha
or token-based verification
in order to prevent automated registration from bad actors.
This check can be disabled by setting the enable_registration_without_verification
option in your
homeserver configuration file to true
. More details are available in the
upgrade notes.
Synapse will additionally now refuse to start when using PostgreSQL with a non-C
values for COLLATE
and CTYPE
, unless
the config flag allow_unsafe_locale
, found in the database section of the configuration file, is set to true
. See the
upgrade notes
for details.
- Bump the version of
black
for compatibility with the latestclick
release. (#12320)
- Allow modules to store already existing 3PID associations. (#12195)
- Allow registering server administrators using the module API. Contributed by Famedly. (#12250)
- Fix a long-standing bug which caused the
/_matrix/federation/v1/state
and/_matrix/federation/v1/state_ids
endpoints to return incorrect or invalid data when called for an event which we have stored as an "outlier". (#12087) - Fix a long-standing bug where events from ignored users would still be considered for relations. (#12227, #12232, #12285)
- Fix a bug introduced in Synapse 1.53.0 where an unnecessary query could be performed when fetching bundled aggregations for threads. (#12228)
- Fix a bug introduced in Synapse 1.52.0 where admins could not deactivate and GDPR-erase a user if Synapse was configured with limits on avatars. (#12261)
- Fix the link to the module documentation in the legacy spam checker warning message. (#12231)
- Remove incorrect prefixes in the worker documentation for some endpoints. (#12243)
- Correct
check_username_for_spam
annotations and docs. (#12246) - Correct Authentik OpenID typo, and add notes on troubleshooting. Contributed by @IronTooch. (#12275)
- HAProxy reverse proxy guide update to stop sending IPv4-mapped address to homeserver. Contributed by @villepeh. (#12279)
- Rename
shared_rooms
tomutual_rooms
(MSC2666), as per proposal changes. (#12036) - Remove check on
update_user_directory
for shared rooms handler (MSC2666), and update/expand documentation. (#12038) - Refactor
create_new_client_event
to use a new parameter,state_event_ids
, which accurately describes the usage with MSC2716 instead of abusingauth_event_ids
. (#12083, #12304) - Refuse to start if registration is enabled without email, captcha, or token-based verification unless the new config flag
enable_registration_without_verification
is set totrue
. (#12091, #12322) - Add tests for database transaction callbacks. (#12198)
- Handle cancellation in
DatabasePool.runInteraction
. (#12199) - Add missing type hints for cache storage. (#12216)
- Add missing type hints for storage. (#12248, #12255)
- Add type hints to tests files. (#12224, #12240, #12256)
- Use type stubs for
psycopg2
. (#12269) - Improve type annotations for
execute_values
. (#12311) - Clean-up logic around rebasing URLs for URL image previews. (#12219)
- Use the
ignored_users
table in additional places instead of re-parsing the account data. (#12225) - Refactor the relations endpoints to add a
RelationsHandler
. (#12237) - Generate announcement links in the release script. (#12242)
- Improve error message when dependencies check finds a broken installation. (#12244)
- Compress metrics HTTP resource when enabled. Contributed by Nick @ Beeper. (#12258)
- Refuse to start if the PostgreSQL database has a non-
C
locale, unless the config flagallow_unsafe_db_locale
is set to true. (#12262, #12288) - Optionally include account validity expiration information to experimental MSC3720 account status responses. (#12266)
- Add a new cache
_get_membership_from_event_id
to speed up push rule calculations in large rooms. (#12272) - Re-enable Complement concurrency in CI. (#12283)
- Remove unused test utilities. (#12291)
- Enhance logging for inbound federation events. (#12301)
- Fix compatibility with the recently-released Jinja 3.1. (#12313)
- Avoid trying to calculate the state at outlier events. (#12314)
This patch version reverts the earlier fixes from Synapse 1.55.1, which could cause problems in certain deployments, and instead adds a cap to the version of Jinja to be installed. Again, this is to fix an incompatibility with version 3.1.0 of the Jinja library, and again, deployments of Synapse using the matrixdotorg/synapse
Docker image or Debian packages from packages.matrix.org are not affected.
- Pin Jinja to <3.1.0, as Synapse fails to start with Jinja 3.1.0. (#12297)
- Revert changes from 1.55.1 as they caused problems with older versions of Jinja (#12296)
This is a patch release that fixes an incompatibility with version 3.1.0 of the Jinja library, released on March 24th, 2022. Deployments of Synapse using the matrixdotorg/synapse
Docker image or Debian packages from packages.matrix.org are not affected.
- Remove uses of the long-deprecated
jinja2.Markup
which would prevent Synapse from starting with Jinja 3.1.0 or above installed. (#12289)
This release removes a workaround introduced in Synapse 1.50.0 for Mjolnir compatibility. This breaks compatibility with Mjolnir 1.3.1 and earlier. (#11700); Mjolnir users should upgrade Mjolnir before upgrading Synapse to this version.
This release also moves the location of the synctl
script; see the upgrade notes for more details.
- Tweak copy for default Single Sign-On account details template to better adhere to mobile app store guidelines. (#12265, #12260)
- Add third-party rules callbacks
check_can_shutdown_room
andcheck_can_deactivate_user
. (#12028) - Improve performance of logging in for large accounts. (#12132)
- Add experimental env var
SYNAPSE_ASYNC_IO_REACTOR
that causes Synapse to use the asyncio reactor for Twisted. (#12135) - Support the stable identifiers from MSC3440: threads. (#12151)
- Add a new Jinja2 template filter to extract the local part of an email address. (#12212)
- Use the proper serialization format for bundled thread aggregations. The bug has existed since Synapse v1.48.0. (#12090)
- Fix a long-standing bug when redacting events with relations. (#12113, #12121, #12130, #12189)
- Fix a bug introduced in Synapse 1.7.2 whereby background updates are never run with the default background batch size. (#12157)
- Fix a bug where non-standard information was returned from the
/hierarchy
API. Introduced in Synapse v1.41.0. (#12175) - Fix a bug introduced in Synapse 1.54.0 that broke background updates on sqlite homeservers while search was disabled. (#12215)
- Fix a long-standing bug when a
filter
argument withevent_fields
which did not include theunsigned
field could result in a 500 error on/sync
. (#12234)
- Fix complexity checking config example in Resource Constrained Devices docs page. (#11998)
- Improve documentation for demo scripts. (#12143)
- Updates to the Room DAG concepts development document. (#12179)
- Document that the
typing
,to_device
,account_data
,receipts
, andpresence
stream writer can only be used on a single worker. (#12196) - Document that contributors can sign off privately by email. (#12204)
- Remove workaround introduced in Synapse 1.50.0 for Mjolnir compatibility. Breaks compatibility with Mjolnir 1.3.1 and earlier. (#11700)
- **
synctl
has been moved into intosynapse._scripts
and is exposed as an entry point; see upgrade notes. (#12140) - Remove backwards compatibilty with pagination tokens from the
/relations
and/aggregations
endpoints generated from Synapse < v1.52.0. (#12138) - The groups/communities feature in Synapse has been deprecated. (#12200)
- Simplify the
ApplicationService
class' set of public methods related to interest checking. (#11915) - Add config settings for background update parameters. (#11980)
- Correct type hints for txredis. (#12042)
- Limit the size of
aggregation_key
on annotations. (#12101) - Add type hints to tests files. (#12108, #12146, #12207, #12208)
- Move scripts to Synapse package and expose as setuptools entry points. (#12118)
- Add support for cancellation to
ReadWriteLock
. (#12120) - Fix data validation to compare to lists, not sequences. (#12128)
- Fix CI not attaching source distributions and wheels to the GitHub releases. (#12131)
- Remove unused mocks from
test_typing
. (#12136) - Give
scripts-dev
scripts suffixes for neater CI config. (#12137) - Move the snapcraft configuration file to
contrib
. (#12142) - Enable MSC3030 Complement tests in CI. (#12144)
- Enable MSC2716 Complement tests in CI. (#12145)
- Add test for
ObservableDeferred
's cancellation behaviour. (#12149) - Use
ParamSpec
in type hints forsynapse.logging.context
. (#12150) - Prune unused jobs from
tox
config. (#12152) - Move CI checks out of tox, to facilitate a move to using poetry. (#12153)
- Avoid generating state groups for local out-of-band leaves. (#12154)
- Avoid trying to calculate the state at outlier events. (#12155, #12173, #12202)
- Fix some type annotations. (#12156)
- Add type hints for
ObservableDeferred
attributes. (#12159) - Use a prebuilt Action for the
tests-done
CI job. (#12161) - Reduce number of DB queries made during processing of
/sync
. (#12163) - Add
delay_cancellation
utility function, which behaves likestop_cancellation
but waits until the originalDeferred
resolves before raising aCancelledError
. (#12180) - Retry HTTP replication failures, this should prevent 502's when restarting stateful workers (main, event persisters, stream writers). Contributed by Nick @ Beeper. (#12182)
- Add cancellation support to
@cached
and@cachedList
decorators. (#12183) - Remove unused variables. (#12187)
- Add combined test for HTTP pusher and push rule. Contributed by Nick @ Beeper. (#12188)
- Rename
HomeServer.get_tcp_replication
toget_replication_command_handler
. (#12192) - Remove some dead code. (#12197)
- Fix a misleading comment in the function
check_event_for_spam
. (#12203) - Remove unnecessary
pass
statements. (#12206) - Update the SSO username picker template to comply with SIWA guidelines. (#12210)
- Improve code documentation for the typing stream over replication. (#12211)
Please note that this will be the last release of Synapse that is compatible with Mjolnir 1.3.1 and earlier. Administrators of servers which have the Mjolnir module installed are advised to upgrade Mjolnir to version 1.3.2 or later.
- Fix a bug introduced in Synapse 1.54.0rc1 preventing the new module callbacks introduced in this release from being registered by modules. (#12141)
- Fix a bug introduced in Synapse 1.54.0rc1 where runtime dependency version checks would mistakenly check development dependencies if they were present and would not accept pre-release versions of dependencies. (#12129, #12177)
- Update release script to insert the previous version when writing "No significant changes" line in the changelog. (#12127)
- Relax the version guard for "packaging" added in #12088. (#12166)
- Add support for MSC3202: sending one-time key counts and fallback key usage states to Application Services. (#11617)
- Improve the generated URL previews for some web pages. Contributed by @AndrewRyanChama. (#11985)
- Track cache invalidations in Prometheus metrics, as already happens for cache eviction based on size or time. (#12000)
- Implement experimental support for MSC3720 (account status endpoints). (#12001, #12067)
- Enable modules to set a custom display name when registering a user. (#12009)
- Advertise Matrix 1.1 and 1.2 support on
/_matrix/client/versions
. (#12020, (#12022) - Support only the stable identifier for MSC3069's
is_guest
on/_matrix/client/v3/account/whoami
. (#12021) - Use room version 9 as the default room version (per MSC3589). (#12058)
- Add module callbacks to react to user deactivation status changes (i.e. deactivations and reactivations) and profile updates. (#12062)
- Fix a bug introduced in Synapse 1.48.0 where an edit of the latest event in a thread would not be properly applied to the thread summary. (#11992)
- Fix long-standing bug where the
get_rooms_for_user
cache was not correctly invalidated for remote users when the server left a room. (#11999) - Fix a 500 error with Postgres when looking backwards with the MSC3030
/timestamp_to_event?dir=b
endpoint. (#12024) - Properly fix a long-standing bug where wrong data could be inserted into the
event_search
table when using SQLite. This could block runningsynapse_port_db
with anargument of type 'int' is not iterable
error. This bug was partially fixed by a change in Synapse 1.44.0. (#12037) - Fix slow performance of
/logout
in some cases where refresh tokens are in use. The slowness existed since the initial implementation of refresh tokens in version 1.38.0. (#12056) - Fix a long-standing bug where Synapse would make additional failing requests over federation for missing data. (#12077)
- Fix occasional
Unhandled error in Deferred
error message. (#12089) - Fix a bug introduced in Synapse 1.51.0 where incoming federation transactions containing at least one EDU would be dropped if debug logging was enabled for
synapse.8631_debug
. (#12098) - Fix a long-standing bug which could cause push notifications to malfunction if
use_frozen_dicts
was set in the configuration. (#12100) - Fix an extremely rare, long-standing bug in
ReadWriteLock
that would cause an error when a newly unblocked writer completes instantly. (#12105) - Make a
POST
to/rooms/<room_id>/receipt/m.read/<event_id>
only trigger a push notification if the count of unread messages is different to the one in the last successfully sent push. This reduces server load and load on the receiving device. (#11835)
- The Docker image no longer automatically creates a temporary volume at
/data
. This is not expected to affect normal usage. (#11997) - Use Python 3.9 in Docker images by default. (#12112)
- Document support for the
to_device
,account_data
,receipts
, andpresence
stream writers for workers. (#11599) - Explain the meaning of spam checker callbacks' return values. (#12003)
- Clarify information about external Identity Provider IDs. (#12004)
- Deprecate using
synctl
with the config optionsynctl_cache_factor
and print a warning if a user still uses this option. (#11865) - Remove support for the legacy structured logging configuration (please see the the upgrade notes if you are using
structured: true
in the Synapse configuration). (#12008) - Drop support for MSC3283 unstable flags now that the stable flags are supported. (#12018)
- Remove the unstable
/spaces
endpoint from MSC2946. (#12073)
- Make the
get_room_version
method useget_room_version_id
to benefit from caching. (#11808) - Remove unnecessary condition on knock -> leave auth rule check. (#11900)
- Add tests for device list changes between local users. (#11972)
- Optimise calculating
device_list
changes in/sync
. (#11974) - Add missing type hints to storage classes. (#11984)
- Refactor the search code for improved readability. (#11991)
- Move common deduplication code down into
_auth_and_persist_outliers
. (#11994) - Limit concurrent joins from applications services. (#11996)
- Preparation for faster-room-join work: when parsing the
send_join
response, get them.room.create
event fromstate
, notauth_chain
. (#12005, #12039) - Preparation for faster-room-join work: parse MSC3706 fields in send_join response. (#12011)
- Preparation for faster-room-join work: persist information on which events and rooms have partial state to the database. (#12012)
- Preparation for faster-room-join work: Support for calling
/federation/v1/state
on a remote server. (#12013) - Configure
tox
to usevenv
rather thanvirtualenv
. (#12015) - Fix bug in
StateFilter.return_expanded()
and add some tests. (#12016) - Use Matrix v1.1 endpoints (
/_matrix/client/v3/auth/...
) in fallback auth HTML forms. (#12019) - Update the
olddeps
CI job to use an old version ofmarkupsafe
. (#12025) - Upgrade Mypy to version 0.931. (#12030)
- Remove legacy
HomeServer.get_datastore()
. (#12031, #12070) - Minor typing fixes. (#12034, #12069)
- After joining a room, create a dedicated logcontext to process the queued events. (#12041)
- Tidy up GitHub Actions config which builds distributions for PyPI. (#12051)
- Move configuration out of
setup.cfg
. (#12052, #12059) - Fix error message when a worker process fails to talk to another worker process. (#12060)
- Fix using the
complement.sh
script without specifying a directory or a branch. Contributed by Nico on behalf of Famedly. (#12063) - Add type hints to
tests/rest/client
. (#12066, #12072, #12084, #12094) - Add some logging to
/sync
to try and track down #11916. (#12068) - Inspect application dependencies using
importlib.metadata
or its backport. (#12088) - Use
assertEqual
instead of the deprecatedassertEquals
in test code. (#12092) - Move experimental support for MSC3440 to
/versions
. (#12099) - Add
stop_cancellation
utility function to stopDeferred
s from being cancelled. (#12106) - Improve exception handling for concurrent execution. (#12109)
- Advertise support for Python 3.10 in packaging files. (#12111)
- Move CI checks out of tox, to facilitate a move to using poetry. (#12119)
No significant changes since 1.53.0rc1.
- Add experimental support for sending to-device messages to application services, as specified by MSC2409. (#11215, #11966)
- Add a background database update to purge account data for deactivated users. (#11655)
- Experimental support for MSC3666: including bundled aggregations in server side search results. (#11837)
- Enable cache time-based expiry by default. The
expiry_time
config flag has been superseded byexpire_caches
andcache_entry_ttl
. (#11849) - Add a callback to allow modules to allow or forbid a 3PID (email address, phone number) from being associated to a local account. (#11854)
- Stabilize support and remove unstable endpoints for MSC3231. Clients must switch to the stable identifier and endpoint. See the upgrade notes for more information. (#11867)
- Allow modules to retrieve the current instance's server name and worker name. (#11868)
- Use a dedicated configurable rate limiter for 3PID invites. (#11892)
- Support the stable API endpoint for MSC3283: new settings in
/capabilities
endpoint. (#11933, #11989) - Support the
dir
parameter on the/relations
endpoint, per MSC3715. (#11941) - Experimental implementation of MSC3706: extensions to
/send_join
to support reduced response size. (#11967)
- Fix MSC2716 historical messages backfilling in random order on remote homeservers. (#11114)
- Fix a bug introduced in Synapse 1.51.0 where incoming federation transactions containing at least one EDU would be dropped if debug logging was enabled for
synapse.8631_debug
. (#11890) - Fix a long-standing bug where some unknown endpoints would return HTML error pages instead of JSON
M_UNRECOGNIZED
errors. (#11930) - Implement an allow list of content types for which we will attempt to preview a URL. This prevents Synapse from making useless longer-lived connections to streaming media servers. (#11936)
- Fix a long-standing bug where pagination tokens from
/sync
and/messages
could not be provided to the/relations
API. (#11952) - Require that modules register their callbacks using keyword arguments. (#11975)
- Fix a long-standing bug where
M_WRONG_ROOM_KEYS_VERSION
errors would not include the speccedcurrent_version
field. (#11988)
- Fix typo in User Admin API: unpind -> unbind. (#11859)
- Document images returned by the User List Media Admin API can include those generated by URL previews. (#11862)
- Remove outdated MSC1711 FAQ document. (#11907)
- Correct the structured logging configuration example. Contributed by Brad Jones. (#11946)
- Add information on the Synapse release cycle. (#11954)
- Fix broken link in the README to the admin API for password reset. (#11955)
- Drop support for
webclient
listeners and configuringweb_client_location
to a non-HTTP(S) URL. Deprecated configurations are a configuration error. (#11895) - Remove deprecated
user_may_create_room_with_invites
spam checker callback. See the upgrade notes for more information. (#11950) - No longer build
.deb
packages for Ubuntu 21.04 Hirsute Hippo, which has now EOLed. (#11961)
- Enhance user registration test helpers to make them more useful for tests involving application services and devices. (#11615, #11616)
- Improve performance when fetching bundled aggregations for multiple events. (#11660, #11752)
- Fix type errors introduced by new annotations in the Prometheus Client library. (#11832)
- Add missing type hints to replication code. (#11856, #11938)
- Ensure that
opentracing
scopes are activated and closed at the right time. (#11869) - Improve opentracing for incoming federation requests. (#11870)
- Improve internal docstrings in
synapse.util.caches
. (#11876) - Do not needlessly clear the
get_users_in_room
andget_users_in_room_with_profiles
caches when any room state changes. (#11878) - Convert
ApplicationServiceTestCase
to usesimple_async_mock
. (#11880) - Remove experimental changes to the default push rules which were introduced in Synapse 1.19.0 but never enabled. (#11884)
- Disable coverage calculation for olddeps build. (#11888)
- Preparation to support sending device list updates to application services. (#11905)
- Add a test that checks users receive their own device list updates down
/sync
. (#11909) - Run Complement tests sequentially. (#11910)
- Various refactors to the application service notifier code. (#11911, #11912)
- Tests: replace mocked
Authenticator
with the real thing. (#11913) - Various refactors to the typing notifications code. (#11914)
- Use the proper type for the
Content-Length
header in theUploadResource
. (#11927) - Remove an unnecessary ignoring of type hints due to fixes in upstream packages. (#11939)
- Add missing type hints. (#11953)
- Fix an import cycle in
synapse.event_auth
. (#11965) - Unpin
frozendict
but exclude the known bad version 2.1.2. (#11969) - Prepare for rename of default Complement branch. (#11971)
- Fetch Synapse's version using a helper from
matrix-common
. (#11979)
No significant changes since 1.52.0rc1.
Note that Twisted 22.1.0
has recently been released, which fixes a security issue
within the Twisted library. We do not believe Synapse is affected by this vulnerability,
though we advise server administrators who installed Synapse via pip to upgrade Twisted
with pip install --upgrade Twisted treq
as a matter of good practice. The Docker image
matrixdotorg/synapse
and the Debian packages from packages.matrix.org
are using the
updated library.
- Remove account data (including client config, push rules and ignored users) upon user deactivation. (#11621, #11788, #11789)
- Add an admin API to reset connection timeouts for remote server. (#11639)
- Add an admin API to get a list of rooms that federate with a given remote homeserver. (#11658)
- Add a config flag to inhibit
M_USER_IN_USE
during registration. (#11743) - Add a module callback to set username at registration. (#11790)
- Allow configuring a maximum file size as well as a list of allowed content types for avatars. (#11846)
- Include the bundled aggregations in the
/sync
response, per MSC2675. (#11612) - Fix a long-standing bug when previewing Reddit URLs which do not contain an image. (#11767)
- Fix a long-standing bug that media streams could cause long-lived connections when generating URL previews. (#11784)
- Include a
prev_content
field in state events sent to Application Services. Contributed by @totallynotvaishnav. (#11798) - Fix a bug introduced in Synapse 0.33.3 causing requests to sometimes log strings such as
HTTPStatus.OK
instead of integer status codes. (#11827)
- Update pypi installation docs to indicate that we now support Python 3.10. (#11820)
- Add missing steps to the contribution submission process in the documentation. Contributed by @sequentialread. (#11821)
- Remove not needed old table of contents in documentation. (#11860)
- Consolidate the
access_token
information at the top of each relevant page in the Admin API documentation. (#11861)
- Drop support for Python 3.6, which is EOL. (#11683)
- Remove the
experimental_msc1849_support_enabled
flag as the features are now stable. (#11843)
- Preparation for database schema simplifications: add
state_key
andrejection_reason
columns toevents
table. (#11792) - Add
FrozenEvent.get_state_key
and use it in a couple of places. (#11793) - Preparation for database schema simplifications: stop reading from
event_reference_hashes
. (#11794) - Drop unused table
public_room_list_stream
. (#11795) - Preparation for reducing Postgres serialization errors: allow setting transaction isolation level. Contributed by Nick @ Beeper. (#11799, #11847)
- Docker: skip the initial amd64-only build and go straight to multiarch. (#11810)
- Run Complement on the Github Actions VM and not inside a Docker container. (#11811)
- Log module names at startup. (#11813)
- Improve type safety of bundled aggregations code. (#11815)
- Correct a type annotation in the event validation logic. (#11817, #11830)
- Minor updates and documentation for database schema delta files. (#11823)
- Workaround a type annotation problem in
prometheus_client
0.13.0. (#11834) - Minor performance improvement in room state lookup. (#11836)
- Fix some indentation inconsistencies in the sample config. (#11838)
- Add type hints to
tests/rest/admin
. (#11851)
No significant changes since 1.51.0rc2.
Synapse 1.51.0 deprecates webclient
listeners and non-HTTP(S) web_client_location
s. Support for these will be removed in Synapse 1.53.0, at which point Synapse will not be capable of directly serving a web client for Matrix. See the upgrade notes.
- Fix a bug introduced in Synapse 1.40.0 that caused Synapse to fail to process incoming federation traffic after handling a large amount of events in a v1 room. (#11806)
This release includes the same bugfix as Synapse 1.51.0rc2.
- Fix a bug introduced in Synapse 1.40.0 that caused Synapse to fail to process incoming federation traffic after handling a large amount of events in a v1 room. (#11806)
- Add
track_puppeted_user_ips
config flag to record client IP addresses against puppeted users, and include the puppeted users in monthly active user counts. (#11561, #11749, #11757) - Include whether the requesting user has participated in a thread when generating a summary for MSC3440. (#11577)
- Return an
M_FORBIDDEN
error code instead ofM_UNKNOWN
when a spam checker module prevents a user from creating a room. (#11672) - Add a flag to the
synapse_review_recent_signups
script to ignore and filter appservice users. (#11675, #11770)
- Fix a long-standing issue which could cause Synapse to incorrectly accept data in the unsigned field of events received over federation. (#11530)
- Fix a long-standing bug where Synapse wouldn't cache a response indicating that a remote user has no devices. (#11587)
- Fix an error that occurs whilst trying to get the federation status of a destination server that was working normally. This admin API was newly introduced in Synapse v1.49.0. (#11593)
- Fix bundled aggregations not being included in the
/sync
response, per MSC2675. (#11612, #11659, #11791) - Fix the
/_matrix/client/v1/room/{roomId}/hierarchy
endpoint returning incorrect fields which have been present since Synapse 1.49.0. (#11667) - Fix preview of some GIF URLs (like tenor.com). Contributed by Philippe Daouadi. (#11669)
- Fix a bug where only the first 50 rooms from a space were returned from the
/hierarchy
API. This has existed since the introduction of the API in Synapse v1.41.0. (#11695) - Fix a bug introduced in Synapse v1.18.0 where password reset and address validation emails would not be sent if their subject was configured to use the 'app' template variable. Contributed by @br4nnigan. (#11710, #11745)
- Make the 'List Rooms' Admin API sort stable. Contributed by Daniël Sonck. (#11737)
- Fix a long-standing bug where space hierarchy over federation would only work correctly some of the time. (#11775)
- Fix a bug introduced in Synapse v1.46.0 that prevented
on_logged_out
module callbacks from being correctly awaited by Synapse. (#11786)
- Warn against using a Let's Encrypt certificate for TLS/DTLS TURN server client connections, and suggest using ZeroSSL certificate instead. This works around client-side connectivity errors caused by WebRTC libraries that reject Let's Encrypt certificates. Contibuted by @AndrewFerr. (#11686)
- Document the new
SYNAPSE_TEST_PERSIST_SQLITE_DB
environment variable in the contributing guide. (#11715) - Document that the minimum supported PostgreSQL version is now 10. (#11725)
- Fix typo in demo docs: differnt. (#11735)
- Update room spec URL in config files. (#11739)
- Mention
python3-venv
andlibpq-dev
dependencies in the contribution guide. (#11740) - Update documentation for configuring login with Facebook. (#11755)
- Update installation instructions to note that Python 3.6 is no longer supported. (#11781)
- Remove the unstable
/send_relation
endpoint. (#11682) - Remove
python_twisted_reactor_pending_calls
Prometheus metric. (#11724) - Remove the
password_hash
field from the response dictionaries of the Users Admin API. (#11576) - Deprecate support for
webclient
listeners and non-HTTP(S)web_client_location
configuration. (#11774, #11783)
- Run
pyupgrade --py37-plus --keep-percent-format
on Synapse. (#11685) - Use buildkit's cache feature to speed up docker builds. (#11691)
- Use
auto_attribs
and native type hints for attrs classes. (#11692, #11768) - Remove debug logging for #4422, which has been closed since Synapse 0.99. (#11693)
- Remove fallback code for Python 2. (#11699)
- Add a test for an edge case in the
/sync
logic. (#11701) - Add the option to write SQLite test dbs to disk when running tests. (#11702)
- Improve Complement test output for Gitub Actions. (#11707)
- Fix docstring on
add_account_data_for_user
. (#11716) - Complement environment variable name change and update
.gitignore
. (#11718) - Simplify calculation of Prometheus metrics for garbage collection. (#11723)
- Improve accuracy of
python_twisted_reactor_tick_time
Prometheus metric. (#11724, #11771) - Minor efficiency improvements when inserting many values into the database. (#11742)
- Invite PR authors to give themselves credit in the changelog. (#11744)
- Add optional debugging to investigate issue 8631. (#11760)
- Remove
log_function
utility function and its uses. (#11761) - Add a unit test that checks both
client
andwebclient
resources will function when simultaneously enabled. (#11765) - Allow overriding complement commit using
COMPLEMENT_REF
. (#11766) - Add some comments and type annotations for
_update_outliers_txn
. (#11776)
This release fixes a bug in Synapse 1.50.0 that could prevent clients from being able to connect to Synapse if the webclient
resource was enabled. Further details are available in this issue.
- Fix a bug introduced in Synapse 1.50.0rc1 that could cause Matrix clients to be unable to connect to Synapse instances with the
webclient
resource enabled. (#11764)
This release contains a critical bug that may prevent clients from being able to connect. As such, it is not recommended to upgrade to 1.50.0. Instead, please upgrade straight to to 1.50.1. Further details are available in this issue.
Please note that we now only support Python 3.7+ and PostgreSQL 10+ (if applicable), because Python 3.6 and PostgreSQL 9.6 have reached end-of-life.
No significant changes since 1.50.0rc2.
This release candidate fixes a federation-breaking regression introduced in Synapse 1.50.0rc1.
- Fix a bug introduced in Synapse v1.0.0 whereby some device list updates would not be sent to remote homeservers if there were too many to send at once. (#11729)
- Fix a bug introduced in Synapse v1.50.0rc1 whereby outbound federation could fail because too many EDUs were produced for device updates. (#11730)
- Document that now the minimum supported PostgreSQL version is 10. (#11725)
- Fix a typechecker problem related to our (ab)use of
nacl.signing.SigningKey
s. (#11714)
- Allow guests to send state events per MSC3419. (#11378)
- Add experimental support for part of MSC3202: allowing application services to masquerade as specific devices. (#11538)
- Add admin API to get users' account data. (#11664)
- Include the room topic in the stripped state included with invites and knocking. (#11666)
- Send and handle cross-signing messages using the stable prefix. (#10520)
- Support unprefixed versions of fallback key property names. (#11541)
- Fix a long-standing bug where relations from other rooms could be included in the bundled aggregations of an event. (#11516)
- Fix a long-standing bug which could cause
AssertionError
s to be written to the log when Synapse was restarted after purging events from the database. (#11536, #11642) - Fix a bug introduced in Synapse 1.17.0 where a pusher created for an email with capital letters would fail to be created. (#11547)
- Fix a long-standing bug where responses included bundled aggregations when they should not, per MSC2675. (#11592, #11623)
- Fix a long-standing bug that some unknown endpoints would return HTML error pages instead of JSON
M_UNRECOGNIZED
errors. (#11602) - Fix a bug introduced in Synapse 1.19.3 which could sometimes cause
AssertionError
s when backfilling rooms over federation. (#11632)
- Update Synapse install command for FreeBSD as the package is now prefixed with
py38
. Contributed by @itchychips. (#11267) - Document the usage of refresh tokens. (#11427)
- Add details for how to configure a TURN server when behind a NAT. Contibuted by @AndrewFerr. (#11553)
- Add references for using Postgres to the Docker documentation. (#11640)
- Fix the documentation link in newly-generated configuration files. (#11678)
- Correct the documentation for
nginx
to use a case-sensitive url pattern. Fixes an error introduced in v1.21.0. (#11680) - Clarify SSO mapping provider documentation by writing
def
orasync def
before the names of methods, as appropriate. (#11681)
- Replace
mock
package by its standard library version. (#11588) - Drop support for Python 3.6 and Ubuntu 18.04. (#11633)
- Allow specific, experimental events to be created without
prev_events
. Used by MSC2716. (#11243) - A test helper (
wait_for_background_updates
) no longer depends on classes defining astore
property. (#11331) - Add type hints to
synapse.appservice
. (#11360) - Add missing type hints to
synapse.config
module. (#11480) - Add test to ensure we share the same
state_group
across the whole historical batch when using the MSC2716/batch_send
endpoint. (#11487) - Refactor
tests.util.setup_test_homeserver
andtests.server.setup_test_homeserver
. (#11503) - Move
glob_to_regex
andre_word_boundary
tomatrix-python-common
. (#11505, #11687) - Use
HTTPStatus
constants in place of literals intests.rest.client.test_auth
. (#11520) - Add a receipt types constant for
m.read
. (#11531) - Clean up
synapse.rest.admin
. (#11535) - Add missing
errcode
toparse_string
andparse_boolean
. (#11542) - Use
HTTPStatus
constants in place of literals insynapse.http
. (#11543) - Add missing type hints to storage classes. (#11546, #11549, #11551, #11555, #11575, #11589, #11594, #11652, #11653, #11654, #11657)
- Fix an inaccurate and misleading comment in the
/sync
code. (#11550) - Add missing type hints to
synapse.logging.context
. (#11556) - Stop populating unused database column
state_events.prev_state
. (#11558) - Minor efficiency improvements in event persistence. (#11560)
- Add some safety checks that storage functions are used correctly. (#11564, #11580)
- Make
get_device
returnNone
if the device doesn't exist rather than raising an exception. (#11565) - Split the HTML parsing code from the URL preview resource code. (#11566)
- Remove redundant
COALESCE()
s aroundCOUNT()
s in database queries. (#11570) - Add missing type hints to
synapse.http
. (#11571) - Add MSC2716 and MSC3030 to
/versions
->unstable_features
to detect server support. (#11582) - Add type hints to
synapse/tests/rest/admin
. (#11590) - Drop end-of-life Python 3.6 and Postgres 9.6 from CI. (#11595)
- Update black version and run it on all the files. (#11596)
- Add opentracing type stubs and fix associated mypy errors. (#11603, #11622)
- Improve OpenTracing support for requests which use a
ResponseCache
. (#11607) - Improve OpenTracing support for incoming HTTP requests. (#11618)
- A number of improvements to opentracing support. (#11619)
- Refactor the way that the
outlier
flag is set on events received over federation. (#11634) - Improve the error messages from
get_create_event_for_room
. (#11638) - Remove redundant
get_current_events_token
method. (#11643) - Convert
namedtuples
toattrs
. (#11665, #11574) - Update the
/capabilities
response to include whether support for MSC3440 is available. (#11690) - Send the
Accept
header in HTTP requests made usingSimpleHttpClient.get_json
. (#11677) - Work around Mjolnir compatibility issue by adding an import for
glob_to_regex
insynapse.util
, where it moved from. (#11696)
Changelogs for older versions can be found here.