matrix-synapse/matrix-synapse.changes

2011 lines
100 KiB
Plaintext
Raw Normal View History

-------------------------------------------------------------------
Thu Jun 11 14:28:57 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- Update to 1.15.0
- Features
- Advertise support for Client-Server API r0.6.0 and remove
related unstable feature flags. (#6585)
- Add an option to disable autojoining rooms for guest
accounts. (#6637)
- For SAML authentication, add the ability to pass email
addresses to be added to new users' accounts via SAML
attributes. Contributed by Christopher Cooper. (#7385)
- Add admin APIs to allow server admins to manage users'
devices. Contributed by @dklimpel. (#7481)
- Add support for generating thumbnails for WebP images.
Previously, users would see an empty box instead of preview
image. Contributed by @WGH-. (#7586)
- Support the standardized m.login.sso user-interactive
authentication flow. (#7630)
- Bugfixes
- Allow new users to be registered via the admin API even if
the monthly active user limit has been reached. Contributed
by @dklimpel. (#7263)
- Fix email notifications not being enabled for new users when
created via the Admin API. (#7267)
- Fix str placeholders in an instance of
PrepareDatabaseException. Introduced in Synapse v1.8.0.
(#7575)
- Fix a bug in automatic user creation during first time login
with m.login.jwt. Regression in v1.6.0. Contributed by @olof.
(#7585)
- Fix a bug causing the cross-signing keys to be ignored when
resyncing a device list. (#7594)
- Fix metrics failing when there is a large number of active
background processes. (#7597)
- Fix bug where returning rooms for a group would fail if it
included a room that the server was not in. (#7599)
- Fix duplicate key violation when persisting read markers.
(#7607)
- Prevent an entire iteration of the device list resync loop
from failing if one server responds with a malformed result.
(#7609)
- Fix exceptions when fetching events from a remote host fails.
(#7622)
- Make synctl restart start synapse if it wasn't running.
(#7624)
- Pass device information through to the login endpoint when
using the login fallback. (#7629)
- Advertise the m.login.token login flow when OpenID Connect is
enabled. (#7631)
- Fix bug in account data replication stream. (#7656)
- Improved Documentation
- Update the OpenBSD installation instructions. (#7587)
- Advertise Python 3.8 support in setup.py. (#7602)
- Add a link to #synapse:matrix.org in the troubleshooting
section of the README. (#7603)
- Clarifications to the admin api documentation. (#7647)
- Internal Changes
- Convert the identity handler to async/await. (#7561)
- Improve query performance for fetching state from a
PostgreSQL database. Contributed by @ilmari. (#7567)
- Speed up processing of federation stream RDATA rows. (#7584)
- Add comment to systemd example to show postgresql dependency.
(#7591)
- Refactor Ratelimiter to limit the amount of expensive config
value accesses. (#7595)
- Convert groups handlers to async/await. (#7600)
- Clean up exception handling in SAML2ResponseResource. (#7614)
- Check that all asynchronous tasks succeed and general cleanup
of MonthlyActiveUsersTestCase and TestMauLimit. (#7619)
- Convert get_user_id_by_threepid to async/await. (#7620)
- Switch to upstream dh-virtualenv rather than our fork for
Debian package builds. (#7621)
- Update CI scripts to check the number in the newsfile
fragment. (#7623)
- Check if the localpart of a Matrix ID is reserved for guest
users earlier in the registration flow, as well as when
responding to requests to /register/available. (#7625)
- Minor cleanups to OpenID Connect integration. (#7628)
- Attempt to fix flaky test:
PhoneHomeStatsTestCase.test_performance_100. (#7634)
- Fix typos of m.olm.curve25519-aes-sha2 and
m.megolm.v1.aes-sha2 in comments, test files. (#7637)
- Convert user directory, state deltas, and stats handlers to
async/await. (#7640)
- Remove some unused constants. (#7644)
- Fix type information on assert_*_is_admin methods. (#7645)
- Convert registration handler to async/await. (#7649)
-------------------------------------------------------------------
Thu Jun 4 20:54:32 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- make sure we do not pull too new prometheus bindings
-------------------------------------------------------------------
Thu May 28 11:05:04 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- Update to 1.14.0
- Features
- Synapse's cache factor can now be configured in
homeserver.yaml by the caches.global_factor setting.
Additionally, caches.per_cache_factors controls the cache
factors for individual caches. (#6391)
- Add OpenID Connect login/registration support. Contributed by
Quentin Gliech, on behalf of les Connecteurs. (#7256, #7457)
- Add room details admin endpoint. Contributed by Awesome
Technologies Innovationslabor GmbH. (#7317)
- Allow for using more than one spam checker module at once.
(#7435)
- Add additional authentication checks for m.room.power_levels
event per MSC2209. (#7502)
- Implement room version 6 per MSC2240. (#7506)
- Add highly experimental option to move event persistence off
master. (#7281, #7374, #7436, #7440, #7475, #7490, #7491,
#7492, #7493, #7495, #7515, #7516, #7517, #7542)
- Bugfixes
- Fix cache config to not apply cache factor to event cache.
Regression in v1.14.0rc1. (#7578)
- Fix bug where ReplicationStreamer was not always started when
replication was enabled. Bug introduced in v1.14.0rc1.
(#7579)
- Fix specifying individual cache factors for caches with
special characters in their name. Regression in v1.14.0rc1.
(#7580)
- Fix a bug where event updates might not be sent over
replication to worker processes after the stream falls
behind. (#7384)
- Allow expired user accounts to log out their device sessions.
(#7443)
- Fix a bug that would cause Synapse not to resync out-of-sync
device lists. (#7453)
- Prevent rooms with 0 members or with invalid version strings
from breaking group queries. (#7465)
- Workaround for an upstream Twisted bug that caused Synapse to
become unresponsive after startup. (#7473)
- Fix Redis reconnection logic that can result in missed
updates over replication if master reconnects to Redis
without restarting. (#7482)
- When sending m.room.member events, omit displayname and
avatar_url if they aren't set instead of setting them to
null. Contributed by Aaron Raimist. (#7497)
- Fix incorrect method label on
synapse_http_matrixfederationclient_{requests,responses}
prometheus metrics. (#7503)
- Ignore incoming presence events from other homeservers if
presence is disabled locally. (#7508)
- Fix a long-standing bug that broke the update remote profile
background process. (#7511)
- Hash passwords as early as possible during password reset.
(#7538)
- Fix bug where a local user leaving a room could fail under
rare circumstances. (#7548)
- Fix "Missing RelayState parameter" error when using user
interactive authentication with SAML for some SAML providers.
(#7552)
- Fix exception 'GenericWorkerReplicationHandler' object has no
attribute 'send_federation_ack', introduced in v1.13.0.
(#7564)
- synctl now warns if it was unable to stop Synapse and will
not attempt to start Synapse if nothing was stopped.
Contributed by Romain Bouyé. (#6590)
- Documentation
- Fix the OIDC client_auth_method value in the sample config.
(#7581)
- Update information about mapping providers for SAML and
OpenID. (#7458)
- Add additional reverse proxy example for Caddy v2.
Contributed by Jeff Peeler. (#7463)
- Fix copy-paste error in ServerNoticesConfig docstring.
Contributed by @ptman. (#7477)
- Improve the formatting of reverse_proxy.md. (#7514)
- Change the systemd worker service to check that the worker
config file exists instead of silently failing. Contributed
by David Vo. (#7528)
- Minor clarifications to the TURN docs. (#7533)
- Internal changes
- Add typing annotations in synapse.federation. (#7382)
- Convert the room handler to async/await. (#7396)
- Improve performance of get_e2e_cross_signing_key. (#7428)
- Improve performance of mark_as_sent_devices_by_remote.
(#7429, #7562)
- Add type hints to the SAML handler. (#7445)
- Remove storage method get_hosts_in_room that is no longer
called anywhere. (#7448)
- Fix some typos in the notice_expiry templates. (#7449)
- Convert the federation handler to async/await. (#7459)
- Convert the search handler to async/await. (#7460)
- Add type hints to synapse.event_auth. (#7505)
- Convert the room member handler to async/await. (#7507)
- Add type hints to room member handler. (#7513)
- Fix typing annotations in tests.replication. (#7518)
- Remove some redundant Python 2 support code. (#7519)
- All endpoints now respond with a 200 OK for OPTIONS requests.
(#7534, #7560)
- Synapse now exports detailed allocator statistics and basic
GC timings as Prometheus metrics (pypy_gc_time_seconds_total
and pypy_memory_bytes) when run under PyPy. Contributed by
Ivan Shapovalov. (#7536)
- Remove Ubuntu Cosmic and Disco from the list of distributions
which we provide .debs for, due to end-of-life. (#7539)
- Make worker processes return a stubbed-out response to GET
/presence requests. (#7545)
- Optimise some references to hs.config. (#7546)
- On upgrade room only send canonical alias once. (#7547)
- Fix some indentation inconsistencies in the sample config.
(#7550)
- Include synapse.http.site in type checking. (#7553)
- Fix some test code to not mangle stacktraces, to make it
easier to debug errors. (#7554)
- Refresh apt cache when building dh_virtualenv docker image.
(#7555)
- Stop logging some expected HTTP request errors as exceptions.
(#7556, #7563)
- Convert sending mail to async/await. (#7557)
- Simplify reap_monthly_active_users. (#7558)
-------------------------------------------------------------------
Tue May 19 14:54:57 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- Update to 1.13.0
This release brings some potential changes necessary for certain
configurations of Synapse:
- If your Synapse is configured to use SSO and have a custom
sso_redirect_confirm_template_dir configuration option set, you
will need to duplicate the new sso_auth_confirm.html,
sso_auth_success.html and sso_account_deactivated.html
templates into that directory.
- Synapse plugins using the complete_sso_login method of
synapse.module_api.ModuleApi should instead switch to the
async/await version, complete_sso_login_async, which includes
additional checks. The former version is now deprecated.
- A bug was introduced in Synapse 1.4.0 which could cause the
room directory to be incomplete or empty if Synapse was
upgraded directly from v1.2.1 or earlier, to versions between
v1.4.0 and v1.12.x.
Please review UPGRADE.rst for more details on these changes and
for general upgrade guidance.
For the complete list of changes please refer to
https://github.com/matrix-org/synapse/releases/tag/v1.13.0
-------------------------------------------------------------------
Thu Apr 23 15:51:48 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- Update to 1.12.4
- Features:
- Always send users their own device updates. (#7160)
- Add support for handling GET requests for account_data on a
worker. (#7311)
- Bugfixes:
- Fix a bug that prevented cross-signing with users on
worker-mode synapses. (#7255)
- Do not treat display names as globs in push rules. (#7271)
- Fix a bug with cross-signing devices belonging to remote
users who did not share a room with any user on the local
homeserver. (#7289)
-------------------------------------------------------------------
Fri Apr 3 12:21:52 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- Update to 1.12.3
- Remove the pin to Pillow 7.0 which was introduced in Synapse
1.12.2, and correctly fix the issue with building the Debian
packages. (#7212)
-------------------------------------------------------------------
Thu Apr 2 18:27:05 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- Update to 1.12.2
- This release fixes an issue with building the debian packages.
-------------------------------------------------------------------
Thu Apr 2 16:28:51 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- Update to 1.12.1
- Fix starting workers when federation sending not split out.
(#7133). Introduced in v1.12.0.
- Avoid importing sqlite3 when using the postgres backend.
Contributed by David Vo. (#7155). Introduced in v1.12.0rc1.
- Fix a bug which could cause outbound federation traffic to stop
working if a client uploaded an incorrect e2e device signature.
(#7177). Introduced in v1.11.0.
-------------------------------------------------------------------
Tue Mar 24 15:31:47 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- use %requires_eq for runtime dependencies to make sure we always
use the versions we built with. we ran into cases where the
distro package was new enough according to the setup dependencies
but those were not up2date with the actual code.
-------------------------------------------------------------------
Mon Mar 23 14:36:36 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- Update to 1.12.0
Synapse may be vulnerable to request-smuggling attacks when it is
used with a reverse-proxy. The vulnerabilties are fixed in
Twisted 20.3.0, and are described in
[CVE-2020-10108](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10108)
and
[CVE-2020-10109](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10109).
For a good introduction to this class of request-smuggling
attacks, see
https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn.
We are not aware of these vulnerabilities being exploited in the
wild, and do not believe that they are exploitable with current
versions of any reverse proxies. Nevertheless, we recommend that
all Synapse administrators ensure that they have the latest
versions of the Twisted library to ensure that their installation
remains secure.
- Features
- Changes related to room alias management
([MSC2432](https://github.com/matrix-org/matrix-doc/pull/2432)):
- Publishing/removing a room from the room directory now
requires the user to have a power level capable of
modifying the canonical alias, instead of the room aliases.
([\#6965](https://github.com/matrix-org/synapse/issues/6965))
- Validate the `alt_aliases` property of canonical alias
events.
([\#6971](https://github.com/matrix-org/synapse/issues/6971))
- Users with a power level sufficient to modify the canonical
alias of a room can now delete room aliases.
([\#6986](https://github.com/matrix-org/synapse/issues/6986))
- Implement updated authorization rules and redaction rules
for aliases events, from
[MSC2261](https://github.com/matrix-org/matrix-doc/pull/2261)
and
[MSC2432](https://github.com/matrix-org/matrix-doc/pull/2432).
([\#7037](https://github.com/matrix-org/synapse/issues/7037))
- Stop sending m.room.aliases events during room creation and
upgrade.
([\#6941](https://github.com/matrix-org/synapse/issues/6941))
- Synapse no longer uses room alias events to calculate room
names for push notifications.
([\#6966](https://github.com/matrix-org/synapse/issues/6966))
- The room list endpoint no longer returns a list of aliases.
([\#6970](https://github.com/matrix-org/synapse/issues/6970))
- Remove special handling of aliases events from
[MSC2260](https://github.com/matrix-org/matrix-doc/pull/2260)
added in v1.10.0rc1.
([\#7034](https://github.com/matrix-org/synapse/issues/7034))
- Expose the `synctl`, `hash_password` and `generate_config`
commands in the snapcraft package. Contributed by @devec0.
([\#6315](https://github.com/matrix-org/synapse/issues/6315))
- Check that server_name is correctly set before running
database updates.
([\#6982](https://github.com/matrix-org/synapse/issues/6982))
- Break down monthly active users by `appservice_id` and emit
via Prometheus.
([\#7030](https://github.com/matrix-org/synapse/issues/7030))
- Render a configurable and comprehensible error page if
something goes wrong during the SAML2 authentication process.
([\#7058](https://github.com/matrix-org/synapse/issues/7058),
[\#7067](https://github.com/matrix-org/synapse/issues/7067))
- Add an optional parameter to control whether other sessions
are logged out when a user's password is modified.
([\#7085](https://github.com/matrix-org/synapse/issues/7085))
- Add prometheus metrics for the number of active pushers.
([\#7103](https://github.com/matrix-org/synapse/issues/7103),
[\#7106](https://github.com/matrix-org/synapse/issues/7106))
- Improve performance when making HTTPS requests to sygnal,
sydent, etc, by sharing the SSL context object between
connections.
([\#7094](https://github.com/matrix-org/synapse/issues/7094))
- Bugfixes
- When a user's profile is updated via the admin API, also
generate a displayname/avatar update for that user in each
room.
([\#6572](https://github.com/matrix-org/synapse/issues/6572))
- Fix a couple of bugs in email configuration handling.
([\#6962](https://github.com/matrix-org/synapse/issues/6962))
- Fix an issue affecting worker-based deployments where
replication would stop working, necessitating a full restart,
after joining a large room.
([\#6967](https://github.com/matrix-org/synapse/issues/6967))
- Fix `duplicate key` error which was logged when rejoining a
room over federation.
([\#6968](https://github.com/matrix-org/synapse/issues/6968))
- Prevent user from setting 'deactivated' to anything other
than a bool on the v2 PUT /users Admin API.
([\#6990](https://github.com/matrix-org/synapse/issues/6990))
- Fix py35-old CI by using native tox package.
([\#7018](https://github.com/matrix-org/synapse/issues/7018))
- Fix a bug causing `org.matrix.dummy_event` to be included in
responses from `/sync`.
([\#7035](https://github.com/matrix-org/synapse/issues/7035))
- Fix a bug that renders UTF-8 text files incorrectly when
loaded from media. Contributed by @TheStranjer.
([\#7044](https://github.com/matrix-org/synapse/issues/7044))
- Fix a bug that would cause Synapse to respond with an error
about event visibility if a client tried to request the state
of a room at a given token.
([\#7066](https://github.com/matrix-org/synapse/issues/7066))
- Repair a data-corruption issue which was introduced in
Synapse 1.10, and fixed in Synapse 1.11, and which could
cause `/sync` to return with 404 errors about missing events
and unknown rooms.
([\#7070](https://github.com/matrix-org/synapse/issues/7070))
- Fix a bug causing account validity renewal emails to be sent
even if the feature is turned off in some cases.
([\#7074](https://github.com/matrix-org/synapse/issues/7074))
- Improved Documentation
- Updated CentOS8 install instructions. Contributed by Richard
Kellner.
([\#6925](https://github.com/matrix-org/synapse/issues/6925))
- Fix `POSTGRES_INITDB_ARGS` in the
`contrib/docker/docker-compose.yml` example docker-compose
configuration.
([\#6984](https://github.com/matrix-org/synapse/issues/6984))
- Change date in [INSTALL.md](./INSTALL.md#tls-certificates)
for last date of getting TLS certificates to November 2019.
([\#7015](https://github.com/matrix-org/synapse/issues/7015))
- Document that the fallback auth endpoints must be routed to
the same worker node as the register endpoints.
([\#7048](https://github.com/matrix-org/synapse/issues/7048))
- Deprecations and Removals
- Remove the unused query_auth federation endpoint per
[MSC2451](https://github.com/matrix-org/matrix-doc/pull/2451).
([\#7026](https://github.com/matrix-org/synapse/issues/7026))
- Internal Changes
- Add type hints to `logging/context.py`.
([\#6309](https://github.com/matrix-org/synapse/issues/6309))
- Add some clarifications to `README.md` in the database schema
directory.
([\#6615](https://github.com/matrix-org/synapse/issues/6615))
- Refactoring work in preparation for changing the event
redaction algorithm.
([\#6874](https://github.com/matrix-org/synapse/issues/6874),
[\#6875](https://github.com/matrix-org/synapse/issues/6875),
[\#6983](https://github.com/matrix-org/synapse/issues/6983),
[\#7003](https://github.com/matrix-org/synapse/issues/7003))
- Improve performance of v2 state resolution for large rooms.
([\#6952](https://github.com/matrix-org/synapse/issues/6952),
[\#7095](https://github.com/matrix-org/synapse/issues/7095))
- Reduce time spent doing GC, by freezing objects on startup.
([\#6953](https://github.com/matrix-org/synapse/issues/6953))
- Minor perfermance fixes to `get_auth_chain_ids`.
([\#6954](https://github.com/matrix-org/synapse/issues/6954))
- Don't record remote cross-signing keys in the `devices`
table.
([\#6956](https://github.com/matrix-org/synapse/issues/6956))
- Use flake8-comprehensions to enforce good hygiene of
list/set/dict comprehensions.
([\#6957](https://github.com/matrix-org/synapse/issues/6957))
- Merge worker apps together.
([\#6964](https://github.com/matrix-org/synapse/issues/6964),
[\#7002](https://github.com/matrix-org/synapse/issues/7002),
[\#7055](https://github.com/matrix-org/synapse/issues/7055),
[\#7104](https://github.com/matrix-org/synapse/issues/7104))
- Remove redundant `store_room` call from
`FederationHandler._process_received_pdu`.
([\#6979](https://github.com/matrix-org/synapse/issues/6979))
- Update warning for incorrect database collation/ctype to
include link to documentation.
([\#6985](https://github.com/matrix-org/synapse/issues/6985))
- Add some type annotations to the database storage classes.
([\#6987](https://github.com/matrix-org/synapse/issues/6987))
- Port `synapse.handlers.presence` to async/await.
([\#6991](https://github.com/matrix-org/synapse/issues/6991),
[\#7019](https://github.com/matrix-org/synapse/issues/7019))
- Add some type annotations to the federation base & client
classes.
([\#6995](https://github.com/matrix-org/synapse/issues/6995))
- Port `synapse.rest.keys` to async/await.
([\#7020](https://github.com/matrix-org/synapse/issues/7020))
- Add a type check to `is_verified` when processing room keys.
([\#7045](https://github.com/matrix-org/synapse/issues/7045))
- Add type annotations and comments to the auth handler.
([\#7063](https://github.com/matrix-org/synapse/issues/7063))
-------------------------------------------------------------------
Tue Mar 3 21:43:02 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- Update to 1.11.1
This release includes a security fix impacting installations
using Single Sign-On (i.e. SAML2 or CAS) for authentication.
Administrators of such installations are encouraged to upgrade as
soon as possible.
- Bugfixes
- Add a confirmation step to the SSO login flow before
redirecting users to the redirect URL.
([b2bd54a2](https://github.com/matrix-org/synapse/commit/b2bd54a2e31d9a248f73fadb184ae9b4cbdb49f9),
[65c73cdf](https://github.com/matrix-org/synapse/commit/65c73cdfec1876a9fec2fd2c3a74923cd146fe0b),
[a0178df1](https://github.com/matrix-org/synapse/commit/a0178df10422a76fd403b82d2b2a4ed28a9a9d1e))
- Fixed set a user as an admin with the admin API `PUT
/_synapse/admin/v2/users/<user_id>`. Contributed by
@dklimpel.
([\#6910](https://github.com/matrix-org/synapse/issues/6910))
- Fix bug introduced in Synapse 1.11.0 which sometimes caused
errors when joining rooms over federation, with `'coroutine'
object has no attribute 'event_id'`.
([\#6996](https://github.com/matrix-org/synapse/issues/6996))
-------------------------------------------------------------------
Fri Feb 21 15:12:49 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- track series file to make updating patches easier
-------------------------------------------------------------------
Fri Feb 21 12:58:18 UTC 2020 - Aleksa Sarai <asarai@suse.com>
- Update to 1.11.0.
* Limit the number of events that can be requested by the backfill federation
API to 100.
* Reject device display names over 100 characters in length to prevent abuse.
* Implement new aliases endpoint as per MSC2432.
* Stop sending m.room.alias events wheng adding / removing aliases. Check
alt_aliases in the latest m.room.canonical_alias event when deleting an
alias.
* Change the default power levels of invites, tombstones and server ACLs for
new rooms.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Tue Feb 18 01:44:41 UTC 2020 - Aleksa Sarai <asarai@suse.com>
- Update to 1.10.1.
* Fix a bug introduced in Synapse 1.10.0 which would cause room state to be
cleared in the database if Synapse was upgraded direct from 1.2.1 or
earlier to 1.10.0.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Wed Feb 12 16:01:46 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- bump requires on python3-signedjson to follow code change
-------------------------------------------------------------------
Wed Feb 12 13:51:08 UTC 2020 - Aleksa Sarai <asarai@suse.com>
- Update to 1.10.0.
WARNING to client developers: As of this release Synapse validates
client_secret parameters in the Client-Server API as per the spec. See #6766
for details.
+ Add experimental support for updated authorization rules for aliases
events, from MSC2260.
+ Variety of E2EE improvements, most notably:
* Fix bug where querying a remote user's device keys that weren't cached
resulted in only returning a single device.
* Fix bug where Synapse didn't invalidate cache of remote users' devices
when Synapse left a room.
* Detect unknown remote devices and mark cache as stale.
* Attempt to resync remote users' devices when detected as stale.
* When a client asks for a remote user's device keys check if the local
cache for that user has been marked as potentially stale.
* Detect unexpected sender keys on remote encrypted events and resync
device lists.
* Fix an issue with cross-signing where device signatures were not sent to
remote servers.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
Accepting request 768057 from home:darix:apps - update to 1.9.1 Fix bug where setting mau_limit_reserved_threepids config would cause Synapse to refuse to start. (#6793) - package cleanup - make sure we have all libraries to actually install the package: - buildrequires all runtime requirements - (build)require python3-typing_extensions - having it use the python package name is not really useful here. - refreshed and renamed better-paths.patch to matrix-synapse-1.4.1-paths.patch - also fix existing synapse user - group to synapse instead of nogroup - home directory to /var/lib/matrix-synapse - shell to /bin/false (which actually exists) - improvements to the logging configuration: - install copy of the current /etc/matrix-synapse/log.yaml as /etc/matrix-synapse/log.systemd.yaml - install /etc/matrix-synapse/log.file.yaml which logs to /var/log/matrix-synapse/homeserver.log - add the log directory /var/log/matrix-synapse/ - added README.SUSE - better way to bootstrap a new config: 1. ExecStartPre would have never worked anyway 2. added %{_sbindir}/matrix-synapse-generate-config Usage: %{_sbindir}/matrix-synapse-generate-config servername - fix group and shell for the synapse user - added better-paths.patch - put the pid file into /run/matrix-synapse/ - use a default logging config in /etc/matrix-synapse/log.yaml to have systemd logging by default - use full path in the service file - actually use source 50 instead of the service file in the tarball - make permissions tighter on the config files as it contains passwords and other secrets: root:synapse u=rwX,g=rX,o= OBS-URL: https://build.opensuse.org/request/show/768057 OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=111
2020-02-03 11:56:06 +01:00
-------------------------------------------------------------------
Tue Jan 28 14:34:39 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- update to 1.9.1
Fix bug where setting mau_limit_reserved_threepids config would
cause Synapse to refuse to start. (#6793)
-------------------------------------------------------------------
Thu Jan 23 16:06:38 UTC 2020 - Marcus Rueckert <mrueckert@suse.de>
- package cleanup
- make sure we have all libraries to actually install the package:
- buildrequires all runtime requirements
- (build)require python3-typing_extensions
- having it use the python package name is not really useful here.
- refreshed and renamed better-paths.patch to
matrix-synapse-1.4.1-paths.patch
- also fix existing synapse user
- group to synapse instead of nogroup
- home directory to /var/lib/matrix-synapse
- shell to /bin/false (which actually exists)
- improvements to the logging configuration:
- install copy of the current /etc/matrix-synapse/log.yaml as
/etc/matrix-synapse/log.systemd.yaml
- install /etc/matrix-synapse/log.file.yaml which logs to
/var/log/matrix-synapse/homeserver.log
- add the log directory /var/log/matrix-synapse/
- added README.SUSE
- better way to bootstrap a new config:
1. ExecStartPre would have never worked anyway
2. added %{_sbindir}/matrix-synapse-generate-config
Usage:
%{_sbindir}/matrix-synapse-generate-config servername
- fix group and shell for the synapse user
- added better-paths.patch
- put the pid file into /run/matrix-synapse/
- use a default logging config in /etc/matrix-synapse/log.yaml
to have systemd logging by default
- use full path in the service file
- actually use source 50 instead of the service file in the tarball
- make permissions tighter on the config files as it contains
passwords and other secrets:
root:synapse u=rwX,g=rX,o=
-------------------------------------------------------------------
Thu Jan 23 13:45:22 UTC 2020 - Aleksa Sarai <asarai@suse.com>
- Update to 1.9.0.
WARNING: As of this release, Synapse no longer supports versions of SQLite
before 3.11, and will refuse to start when configured to use an older
version. Administrators are recommended to migrate their database to Postgres
(see instructions here).
WARNING: If your Synapse deployment uses workers, note that the reverse-proxy
configurations for the synapse.app.media_repository,
synapse.app.federation_reader and synapse.app.event_creator workers have
changed, with the addition of a few paths (see the updated configurations
here). Existing configurations will continue to work.
+ Allow admin to create or modify a user.
+ Add new quarantine media admin APIs to quarantine by media ID or by user
who uploaded the media.
+ Add a new admin API to list and filter rooms on the server.
+ Add org.matrix.e2e_cross_signing to unstable_features in /versions.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Fri Jan 10 13:41:50 UTC 2020 - Aleksa Sarai <asarai@suse.com>
- Update to 1.8.0.
WARNING: As of this release Synapse will refuse to start if the log_file
config option is specified. Support for the option was removed in v1.3.0.
* Add v2 APIs for the send_join and send_leave federation endpoints (as
described in MSC1802).
* Add a develop script to generate full SQL schemas.
* Add custom SAML username mapping functinality through an external provider
plugin.
* Automatically delete empty groups/communities.
* Add option limit_profile_requests_to_users_who_share_rooms to prevent
requirement of a local user sharing a room with another user to query their
profile information.
* Add an export_signing_key script to extract the public part of signing keys
when rotating them.
* Add experimental config option to specify multiple databases.
* Raise an error if someone tries to use the log_file config option.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Wed Jan 1 03:26:40 UTC 2020 - Aleksa Sarai <asarai@suse.com>
- Update to 1.7.3.
* Fix exceptions caused by state resolution choking on malformed events.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Sat Dec 21 00:57:27 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Use packaged service file not the one in the repo (the one in the repo is
completely broken for openSUSE).
-------------------------------------------------------------------
Fri Dec 20 18:09:31 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 1.7.2.
* Fix a regression introduced in Synapse 1.7.1 which caused errors when
attempting to backfill rooms over federation.
* Fix a bug introduced in Synapse 1.7.0 which caused an error on startup when
upgrading from versions before 1.3.0.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Wed Dec 18 12:02:59 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 1.7.1.
This update fixes several major security issues. Users are very strongly
recommended to update as soon as possible.
* Fix a bug which could cause room events to be incorrectly authorized using
events from a different room.
* Fix a bug causing responses to the /context client endpoint to not use the
pruned version of the event.
* Fix a cause of state resets in room versions 2 onwards.
* Fix a bug which could cause the federation server to incorrectly return
errors when handling certain obscure event graphs.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Fri Dec 13 13:23:59 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 1.7.0.
* Implement per-room message retention policies.
* Add etag and count fields to key backup endpoints to help clients guess if
there are new keys.
* Configure privacy-preserving settings by default for the room directory.
* Add ephemeral messages support by partially implementing MSC2228.
* Add support for MSC 2367, which allows specifying a reason on all
membership events.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
Accepting request 768057 from home:darix:apps - update to 1.9.1 Fix bug where setting mau_limit_reserved_threepids config would cause Synapse to refuse to start. (#6793) - package cleanup - make sure we have all libraries to actually install the package: - buildrequires all runtime requirements - (build)require python3-typing_extensions - having it use the python package name is not really useful here. - refreshed and renamed better-paths.patch to matrix-synapse-1.4.1-paths.patch - also fix existing synapse user - group to synapse instead of nogroup - home directory to /var/lib/matrix-synapse - shell to /bin/false (which actually exists) - improvements to the logging configuration: - install copy of the current /etc/matrix-synapse/log.yaml as /etc/matrix-synapse/log.systemd.yaml - install /etc/matrix-synapse/log.file.yaml which logs to /var/log/matrix-synapse/homeserver.log - add the log directory /var/log/matrix-synapse/ - added README.SUSE - better way to bootstrap a new config: 1. ExecStartPre would have never worked anyway 2. added %{_sbindir}/matrix-synapse-generate-config Usage: %{_sbindir}/matrix-synapse-generate-config servername - fix group and shell for the synapse user - added better-paths.patch - put the pid file into /run/matrix-synapse/ - use a default logging config in /etc/matrix-synapse/log.yaml to have systemd logging by default - use full path in the service file - actually use source 50 instead of the service file in the tarball - make permissions tighter on the config files as it contains passwords and other secrets: root:synapse u=rwX,g=rX,o= OBS-URL: https://build.opensuse.org/request/show/768057 OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=111
2020-02-03 11:56:06 +01:00
https://github.com/matrix-org/synapse/releases/tag/v1.7.0
Please make sure to read the Upgrade notes referenced in the
Accepting request 768057 from home:darix:apps - update to 1.9.1 Fix bug where setting mau_limit_reserved_threepids config would cause Synapse to refuse to start. (#6793) - package cleanup - make sure we have all libraries to actually install the package: - buildrequires all runtime requirements - (build)require python3-typing_extensions - having it use the python package name is not really useful here. - refreshed and renamed better-paths.patch to matrix-synapse-1.4.1-paths.patch - also fix existing synapse user - group to synapse instead of nogroup - home directory to /var/lib/matrix-synapse - shell to /bin/false (which actually exists) - improvements to the logging configuration: - install copy of the current /etc/matrix-synapse/log.yaml as /etc/matrix-synapse/log.systemd.yaml - install /etc/matrix-synapse/log.file.yaml which logs to /var/log/matrix-synapse/homeserver.log - add the log directory /var/log/matrix-synapse/ - added README.SUSE - better way to bootstrap a new config: 1. ExecStartPre would have never worked anyway 2. added %{_sbindir}/matrix-synapse-generate-config Usage: %{_sbindir}/matrix-synapse-generate-config servername - fix group and shell for the synapse user - added better-paths.patch - put the pid file into /run/matrix-synapse/ - use a default logging config in /etc/matrix-synapse/log.yaml to have systemd logging by default - use full path in the service file - actually use source 50 instead of the service file in the tarball - make permissions tighter on the config files as it contains passwords and other secrets: root:synapse u=rwX,g=rX,o= OBS-URL: https://build.opensuse.org/request/show/768057 OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=111
2020-02-03 11:56:06 +01:00
above.
-------------------------------------------------------------------
Thu Nov 28 17:41:02 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Drop matrix-synapse-ldap from enabled conditional requirements, because the
package is not longer available in openSUSE repos. If someone really wants
the feature they can help re-package it.
-------------------------------------------------------------------
Thu Nov 28 12:04:57 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 1.6.1.
* Clean up local threepids from user on account deactivation.
* Fix startup error when http proxy is defined.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Thu Nov 28 08:48:16 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 1.6.0.
+ Add federation support for cross-signing.
+ Increase default room version from 4 to 5, thereby enforcing server key
validity period checks.
+ Add support for outbound http proxying via http_proxy/HTTPS_PROXY env vars.
+ Implement label-based filtering on /sync and /messages (MSC2326).
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Mon Nov 18 11:16:03 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 1.5.1.
* Limit the length of data returned by url previews, to prevent DoS attacks.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Wed Oct 30 02:20:29 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 1.5.0.
+ Improve quality of thumbnails for 1-bit/8-bit color palette images.
+ Add ability to upload cross-signing signatures.
+ Allow uploading of cross-signing keys.
+ CAS login now provides a default display name for users if a
displayname_attribute is set in the configuration file.
+ Reject all pending invites for a user during deactivation.
+ Add config option to suppress client side resource limit alerting.
* Improve signature checking on some federation APIs.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Fri Oct 18 13:36:18 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 1.4.1.
* Fix bug where redacted events were sometimes incorrectly censored in the
database, breaking APIs that attempted to fetch such events.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Thu Oct 3 22:16:13 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Do not include ACME support by default (txacme is broken in openSUSE).
- Update to 1.4.0. boo#1153017
* Significant improvements to data privacy.
* Expansion of OpenTracing support.
* Enable "forward extremities" mitigation by default.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Thu Jul 25 16:18:56 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 1.2.0.
* Add support for OpenTracing.
* Add default push rule to ignore reactions.
* Enable aggregations (reactions and edits) support by default.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
- Remove unneeded patches:
- 0001-requirements-prometheus_client.patch
-------------------------------------------------------------------
Fri Jul 5 15:29:57 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 1.1.0.
As of v1.1.0, Synapse no longer supports Python 2, nor Postgres version 9.4.
Thus, we no longer package a Python 2 version of this package. Some other key
changes include:
* Add monthly active users to phonehome stats.
* Allow server admins to define implementations of extra rules for allowing
or denying incoming events.
* Add --data-dir and --open-private-ports options.
* The minimum TLS version used for outgoing federation requests can now be
set with federation_client_minimum_tls_version.
* Optimise devices changed query to not pull unnecessary rows from the
database, reducing database load.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
- Rebase patches:
* 0001-requirements-prometheus_client.patch
-------------------------------------------------------------------
Fri Jun 28 08:16:05 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Obsolete the old split-Python packages, so that upgrading works smoothly.
-------------------------------------------------------------------
Tue Jun 25 10:48:03 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Un-Requires prometheus_client<0.4.0. The Requires made it impossible to use
matrix-synapse on openSUSE for very little good reason (prometheus metrics
will still work on post-0.4.0 prometheus_client, but with changed names).
Debian and many other distributions do the same here.
+ 0001-requirements-prometheus_client.patch
-------------------------------------------------------------------
Wed Jun 12 02:26:48 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 1.0.0.
This is the first stable release of synapse. It includes a large number of
changes but the highlights are:
* Ability to configured default room version (with the default now being v4,
which has improved state resolution algorithms and event IDs).
* The complete removal of "perspectives" support, with all homeservers now
being required to use valid TLS certificates (there has been a transition
period for several months from the release of 0.99).
* Experimental support for "relations" (reactions and edits).
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Fri May 31 00:04:50 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 0.99.5.2.
Fix bug where we leaked extremities when we soft failed events, leading to
performance degradation.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Tue May 28 01:18:34 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Rework testing to use a separate specfile for testing matrix-synapse.
-------------------------------------------------------------------
Thu May 23 00:13:47 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 0.99.5.1.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Wed May 15 13:19:23 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 0.99.4.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Wed May 8 00:47:56 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 0.99.3.2.
This includes two security fixes:
* Switch to using a cryptographically-secure random number generator for
token strings, ensuring they cannot be predicted by an attacker.
* Blacklist 0.0.0.0 and :: by default for URL previews.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Sun Apr 14 18:35:48 UTC 2019 - Aleksa Sarai <asarai@suse.com>
- Update to 0.99.3.
The primary changes to previous versions are that self-signed certificates
will no longer be generated, and instead LetsEncrypt certificates will be
requested instead. Users are strongly recommended to update to this version,
because pre-0.99 servers (using self-signed certificates and the perspectives
system) will no longer be able to federate with post-1.0 servers.
The full changelog is included in
/usr/share/doc/packages/matrix-synapse/CHANGES.md.
-------------------------------------------------------------------
Wed Feb 20 11:42:00 UTC 2019 - Oliver Kurz <okurz@suse.com>
- Fix build on python3 based repos
-------------------------------------------------------------------
Sat Feb 2 15:32:06 UTC 2019 - fcrozat@suse.com
- Fix systemd service to follow paths used by package and ensure
proper version version is used.
- Add explicit requires on python-lxml, required when using
url preview.
-------------------------------------------------------------------
Mon Jan 14 07:44:26 UTC 2019 - ecsos@opensuse.org
- For test purpose a matrix server will be start. But never been
stopped. Fix that server will be stoped after test.
-------------------------------------------------------------------
Sun Jan 13 18:22:20 UTC 2019 - Oliver Kurz <okurz@suse.com>
- Update to 0.34.1.1
This release fixes CVE-2019-5885 and is recommended for all users of Synapse
0.34.1. This release is compatible with Python 2.7 and 3.5+. Python 3.7 is
fully supported.
* Bugfixes
- Fix spontaneous logout on upgrade (#4374)
* Internal Changes
- Add better logging for unexpected errors while sending transactions
(#4361, #4362)
- Getting URL previews of IP addresses no longer fails on Python 3.
(#4215)
- drop undocumented dependency on dateutil (#4266)
- Update the example systemd config to use a virtualenv (#4273)
- Update link to kernel DCO guide (#4274)
- Make isort tox check print diff when it fails (#4283)
- Log room_id in Unknown room errors (#4297)
- Documentation improvements for coturn setup. Contributed by Krithin
Sitaram. (#4333)
- Update pull request template to use absolute links (#4341)
- Update README to not lie about required restart when updating TLS
certificates (#4343)
- Update debian packaging for compatibility with transitional package
(#4349)
- Fix command hint to generate a config file when trying to start without
a config file (#4353)
- Add better logging for unexpected errors while sending transactions
(#4358)
* Features
- Special-case a support user for use in verifying behaviour of a given
server. The support user does not appear in user directory or monthly
active user counts. (#4141, #4344)
- Support for serving .well-known files (#4262)
- Rework SAML2 authentication (#4265, #4267)
- SAML2 authentication: Initialise user display name from SAML2 data
(#4272)
- Synapse can now have its conditional/extra dependencies installed by
pip. This functionality can be used by using `pip install
matrix-synapse[feature]`, where feature is a comma separated list with
the possible values `email.enable_notifs`, `matrix-synapse-ldap3`,
`postgres`, `resources.consent`, `saml2`, `url_preview`, and `test`. If
you want to install all optional dependencies, you can use "all"
instead. (#4298, #4325, #4327)
- Add routes for reading account data. (#4303)
- Add opt-in support for v2 rooms (#4307)
- Add a script to generate a clean config file (#4315)
- Return server data in /login response (#4319)
* Bugfixes
- Fix contains_url check to be consistent with other instances in
code-base and check that value is an instance of string. (#3405)
- Fix CAS login when username is not valid in an MXID (#4264)
- Send CORS headers for /media/config (#4279)
- Add 'sandbox' to CSP for media reprository (#4284)
- Make the new landing page prettier. (#4294)
- Fix deleting E2E room keys when using old SQLite versions. (#4295)
- The metric synapse_admin_mau:current previously did not update when
config.mau_stats_only was set to True (#4305)
- Fixed per-room account data filters (#4309)
- Fix indentation in default config (#4313)
- Fix synapse:latest docker upload (#4316)
- Fix test_metric.py compatibility with prometheus_client 0.5. Contributed
by Maarten de Vries <maarten@de-vri.es>. (#4317)
- Avoid packaging _trial_temp directory in -py3 debian packages (#4326)
- Check jinja version for consent resource (#4327)
- fix NPE in /messages by checking if all events were filtered out (#4330)
- Fix `python -m synapse.config` on Python 3. (#4356)
* Deprecations and Removals
- Remove the deprecated v1/register API on Python 2. It was never ported
to Python 3. (#4334)
-------------------------------------------------------------------
Sat Dec 29 10:11:21 UTC 2018 - Oliver Kurz <okurz@suse.com>
- Switch to python3 by default on newer product versions as suggested by upstream
-------------------------------------------------------------------
Sun Dec 23 10:00:29 UTC 2018 - ecsos@opensuse.org
- Update to 0.34.0
Synapse 0.34.0 is the first release to fully support Python 3.
Synapse will now run on Python versions 3.5 or 3.6
(as well as 2.7). Support for Python 3.7 remains experimental.
* Features
- Add 'sandbox' to CSP for media reprository (#4284)
- Make the new landing page prettier. (#4294)
- Fix deleting E2E room keys when using old SQLite versions. (#4295)
- Add a welcome page for the client API port. Credit to @krombel! (#4289)
- Remove Matrix console from the default distribution (#4290)
- Add option to track MAU stats (but not limit people) (#3830)
- Add an option to enable recording IPs for appservice users (#3831)
- Rename login type m.login.cas to m.login.sso (#4220)
- Add an option to disable search for homeservers that may not be interested in it. (#4230)
* Bugfixes
- Pushrules can now again be made with non-ASCII rule IDs. (#4165)
- The media repository now no longer fails to decode UTF-8 filenames when downloading remote media. (#4176)
- URL previews now correctly decode non-UTF-8 text if the header contains a <meta http-equiv="Content-Type" header. (#4183)
- Fix an issue where public consent URLs had two slashes. (#4192)
- Fallback auth now accepts the session parameter on Python 3. (#4197)
- Remove riot.im from the list of trusted Identity Servers in the default configuration (#4207)
- fix start up failure when mau_limit_reserved_threepids set and db is postgres (#4211)
- Fix auto join failures for servers that require user consent (#4223)
- Fix exception caused by non-ascii event IDs (#4241)
- Pushers can now be unsubscribed from on Python 3. (#4250)
- Fix UnicodeDecodeError when postgres is configured to give non-English errors (#4253)
* Internal Changes
- Debian packages utilising a virtualenv with bundled dependencies can now be built. (#4212)
- Disable pager when running git-show in CI (#4291)
- A coveragerc file has been added. (#4180)
- Add a GitHub pull request template and add multiple issue templates (#4182)
- Update README to reflect the fact that #1491 is fixed (#4188)
- Run the AS senders as background processes to fix warnings (#4189)
- Add some diagnostics to the tests to detect logcontext problems (#4190)
- Add missing jpeg package prerequisite for OpenBSD in README. (#4193)
- Add a note saying you need to manually reclaim disk space after using the Purge History API (#4200)
- More logcontext checking in unittests (#4205)
- Ignore __pycache__ directories in the database schema folder (#4214)
- Add note to UPGRADE.rst about removing riot.im from list of trusted identity servers (#4224)
- Added automated coverage reporting to CI. (#4225)
- Garbage-collect after each unit test to fix logcontext leaks (#4227)
- add more detail to logging regarding "More than one row matched" error (#4234)
- Drop sent_transactions table (#4244)
- Add a basic .editorconfig (#4257)
- Update README.rst and UPGRADE.rst for Python 3. (#4260)
- Remove obsolete verbose and log_file settings from homeserver.yaml for Docker image. (#4261)
-------------------------------------------------------------------
Wed Nov 21 18:47:13 UTC 2018 - ecsos@opensuse.org
- Update to 0.33.9
* Features
- Include flags to optionally add m.login.terms to the registration flow when consent tracking is enabled. (#4004, #4133, #4142, #4184)
- Support for replacing rooms with new ones (#4091, #4099, #4100, #4101)
* Bugfixes
- Fix exceptions when using the email mailer on Python 3. (#4095)
- Fix e2e key backup with more than 9 backup versions (#4113)
- Searches that request profile info now no longer fail with a 500. (#4122)
- fix return code of empty key backups (#4123)
- If the typing stream ID goes backwards (as on a worker when the master restarts), the worker's typing handler will no longer
erroneously report rooms containing new typing events. (#4127)
- Fix table lock of device_lists_remote_cache which could freeze the application (#4132)
- Fix exception when using state res v2 algorithm (#4135)
- Generating the user consent URI no longer fails on Python 3. (#4140, #4163)
- Loading URL previews from the DB cache on Postgres will no longer cause Unicode type errors when responding to the request,
and URL - - previews will no longer fail if the remote server returns a Content-Type header with the chartype in quotes. (#4157)
- The hash_password script now works on Python 3. (#4161)
- Fix noop checks when updating device keys, reducing spurious device list update notifications. (#4164)
* Deprecations and Removals
- The disused and un-specced identicon generator has been removed. (#4106)
- The obsolete and non-functional /pull federation endpoint has been removed. (#4118)
- The deprecated v1 key exchange endpoints have been removed. (#4119)
- Synapse will no longer fetch keys using the fallback deprecated v1 key exchange method and will now always use v2. (#4120)
* Internal Changes
- Fix build of Docker image with docker-compose (#3778)
- Delete unreferenced state groups during history purge (#4006)
- The "Received rdata" log messages on workers is now logged at DEBUG, not INFO. (#4108)
- Reduce replication traffic for device lists (#4109)
- Fix synapse_replication_tcp_protocol_*_commands metric label to be full command name, rather than just the first character (#4110)
- Log some bits about room creation (#4121)
- Fix tox failure on old systems (#4124)
- Add STATE_V2_TEST room version (#4128)
- Clean up event accesses and tests (#4137)
- The default logging config will now set an explicit log file encoding of UTF-8. (#4138)
- Add helpers functions for getting prev and auth events of an event (#4139)
- Add some tests for the HTTP pusher. (#4149)
- add purge_history.sh and purge_remote_media.sh scripts to contrib/ (#4155)
- HTTP tests have been refactored to contain less boilerplate. (#4156)
- Drop incoming events from federation for unknown rooms (#4165)
-------------------------------------------------------------------
Thu Nov 1 22:28:54 UTC 2018 - ecsos@opensuse.org
- Update to 0.33.8
* Features
- Servers with auto-join rooms will now automatically create those rooms when the first user registers (#3975)
- Add config option to control alias creation (#4051)
- The register_new_matrix_user script is now ported to Python 3. (#4085)
- Configure Docker image to listen on both ipv4 and ipv6. (#4089)
* Bugfixes
- Fix HTTP error response codes for federated group requests. (#3969)
- Fix issue where Python 3 users couldn't paginate /publicRooms (#4046)
- Fix URL previewing to work in Python 3.7 (#4050)
- synctl will use the right python executable to run worker processes (#4057)
- Manhole now works again on Python 3, instead of failing with a "couldn't match all kex parts" when connecting. (#4060, #4067)
- Fix some metrics being racy and causing exceptions when polled by Prometheus. (#4061)
- Fix bug which prevented email notifications from being sent unless an absolute path was given for email_templates. (#4068)
- Correctly account for cpu usage by background threads (#4074)
- Fix race condition where config defined reserved users were not being added to
- the monthly active user list prior to the homeserver reactor firing up (#4081)
- Fix bug which prevented backslashes being used in event field filters (#4083)
* Internal Changes
- Add information about the matrix-docker-ansible-deploy playbook (#3698)
- Add initial implementation of new state resolution algorithm (#3786)
- Reduce database load when fetching state groups (#4011)
- Various cleanups in the federation client code (#4031)
- Run the CircleCI builds in docker containers (#4041)
- Only colourise synctl output when attached to tty (#4049)
- Refactor room alias creation code (#4063)
- Make the Python scripts in the top-level scripts folders meet pep8 and pass flake8. (#4068)
- The README now contains example for the Caddy web server. Contributed by steamp0rt. (#4072)
- Add psutil as an explicit dependency (#4073)
- Clean up threading and logcontexts in pushers (#4075)
- Correctly manage logcontexts during startup to fix some "Unexpected logging context" warnings (#4076)
- Give some more things logcontexts (#4077)
- Clean up some bits of code which were flagged by the linter (#4082)
-------------------------------------------------------------------
Thu Oct 18 20:32:10 UTC 2018 - ecsos@opensuse.org
- Update to 0.33.7
* Features
- Ship the example email templates as part of the package (#4052)
- Add support for end-to-end key backup (MSC1687) (#4019)
* Bugfixes
- Fix bug which made get_missing_events return too few events (#4045)
- Fix bug in event persistence logic which caused 'NoneType is not iterable' (#3995)
- Fix exception in background metrics collection (#3996)
- Fix exception handling in fetching remote profiles (#3997)
- Fix handling of rejected threepid invites (#3999)
- Workers now start on Python 3. (#4027)
- Synapse now starts on Python 3.7. (#4033)
* Internal Changes
- Log exceptions in looping calls (#4008)
- Optimisation for serving federation requests (#4017)
- Add metric to count number of non-empty sync responses (#4022)
-------------------------------------------------------------------
Sat Oct 6 08:42:56 UTC 2018 - ecsos@opensuse.org
- Update to 0.33.6
* Features
- Adding the ability to change MAX_UPLOAD_SIZE for the docker container variables. (#3883)
- Report "python_version" in the phone home stats (#3894)
- Always LL ourselves if we're in a room (#3916)
- Include eventid in log lines when processing incoming federation transactions (#3959)
- Remove spurious check which made 'localhost' servers not work (#3964)
* Bugfixes
- Fix problem when playing media from Chrome using direct URL (thanks @remjey!) (#3578)
- support registering regular users non-interactively with register_new_matrix_user script (#3836)
- Fix broken invite email links for self hosted riots (#3868)
- Don't ratelimit autojoins (#3879)
- Fix 500 error when deleting unknown room alias (#3889)
- Fix some b'abcd' noise in logs and metrics (#3892, #3895)
- When we join a room, always try the server we used for the alias lookup first, to avoid unresponsive and out-of-date servers. (#3899)
- Fix incorrect server-name indication for outgoing federation requests (#3907)
- Fix adding client IPs to the database failing on Python 3. (#3908)
- Fix bug where things occaisonally were not being timed out correctly. (#3910)
- Fix bug where outbound federation would stop talking to some servers when using workers (#3914)
- Fix some instances of ExpiringCache not expiring cache items (#3932, #3980)
- Fix out-of-bounds error when LLing yourself (#3936)
- Sending server notices regarding user consent now works on Python 3. (#3938)
- Fix exceptions from metrics handler (#3956)
- Fix error message for events with m.room.create missing from auth_events (#3960)
- Fix errors due to concurrent monthly_active_user upserts (#3961)
- Fix exceptions when processing incoming events over federation (#3968)
- Replaced all occurences of e.message with str(e). Contributed by Schnuffle (#3970)
- Fix lazy loaded sync in the presence of rejected state events (#3986)
- Fix error when logging incomplete HTTP requests (#3990)
* Internal Changes
- Unit tests can now be run under PostgreSQL in Docker using test_postgresql.sh. (#3699)
- Speed up calculation of typing updates for replication (#3794)
- Remove documentation regarding installation on Cygwin, the use of WSL is recommended instead. (#3873)
- Fix typo in README, synaspse -> synapse (#3897)
- Increase the timeout when filling missing events in federation requests (#3903)
- Improve the logging when handling a federation transaction (#3904, #3966)
- Improve logging of outbound federation requests (#3906, #3909)
- Fix the docker image building on python 3 (#3911)
- Add a regression test for logging failed HTTP requests on Python 3. (#3912)
- Comments and interface cleanup for on_receive_pdu (#3924)
- Fix spurious exceptions when remote http client closes conncetion (#3925)
- Log exceptions thrown by background tasks (#3927)
- Add a cache to get_destination_retry_timings (#3933, #3991)
- Automate pushes to docker hub (#3946)
- Require attrs 16.0.0 or later (#3947)
- Fix incompatibility with python3 on alpine (#3948)
- Run the test suite on the oldest supported versions of our dependencies in CI. (#3952)
- CircleCI now only runs merged jobs on PRs, and commit jobs on develop, master, and release branches. (#3957)
- Fix docstrings and add tests for state store methods (#3958)
- fix docstring for FederationClient.get_state_for_room (#3963)
- Run notify_app_services as a bg process (#3965)
- Clarifications in FederationHandler (#3967)
- Further reduce the docker image size (#3972)
- Build py3 docker images for docker hub too (#3976)
- Updated the installation instructions to point to the matrix-synapse package on PyPI. (#3985)
- Disable USE_FROZEN_DICTS for unittests by default. (#3987)
- Remove unused Jenkins and development related files from the repo. (#3988)
- Improve stacktraces in certain exceptions in the logs (#3989)
- Pin to prometheus_client<0.4 to avoid renaming all of our metrics (#4002)
- Changes from 0.33.5.1
* Internal Changes
- Fix incompatibility with older Twisted version in tests. Thanks @OlegGirko! (#3940)
- Changes from 0.33.5
* Features
- Python 3.5 and 3.6 support is now in beta. (#3576)
- Implement event_format filter param in /sync (#3790)
- Add synapse_admin_mau:registered_reserved_users metric to expose number of real reaserved users (#3846)
* Bugfixes
- Remove connection ID for replication prometheus metrics, as it creates a large number of new series. (#3788)
- guest users should not be part of mau total (#3800)
- Bump dependency on pyopenssl 16.x, to avoid incompatibility with recent Twisted. (#3804)
- Fix existing room tags not coming down sync when joining a room (#3810)
- Fix jwt import check (#3824)
- fix VOIP crashes under Python 3 (#3821) (#3835)
- Fix manhole so that it works with latest openssh clients (#3841)
- Fix outbound requests occasionally wedging, which can result in federation breaking between servers. (#3845)
- Show heroes if room name/canonical alias has been deleted (#3851)
- Fix handling of redacted events from federation (#3859)
- (#3874)
- Mitigate outbound federation randomly becoming wedged (#3875)
* Internal Changes
- CircleCI tests now run on the potential merge of a PR. (#3704)
- http/ is now ported to Python 3. (#3771)
- Improve human readable error messages for threepid registration/account update (#3789)
- Make /sync slightly faster by avoiding needless copies (#3795)
- handlers/ is now ported to Python 3. (#3803)
- Limit the number of PDUs/EDUs per federation transaction (#3805)
- Only start postgres instance for postgres tests on Travis CI (#3806)
- tests/ is now ported to Python 3. (#3808)
- crypto/ is now ported to Python 3. (#3822)
- rest/ is now ported to Python 3. (#3823)
- add some logging for the keyring queue (#3826)
- speed up lazy loading by 2-3x (#3827)
- Improved Dockerfile to remove build requirements after building reducing the image size. (#3834)
- Disable lazy loading for incremental syncs for now (#3840)
- federation/ is now ported to Python 3. (#3847)
- Log when we retry outbound requests (#3853)
- Removed some excess logging messages. (#3855)
- Speed up purge history for rooms that have been previously purged (#3856)
- Refactor some HTTP timeout code. (#3857)
- Fix running merged builds on CircleCI (#3858)
- Fix typo in replication stream exception. (#3860)
- Add in flight real time metrics for Measure blocks (#3871)
- Disable buffering and automatic retrying in treq requests to prevent timeouts. (#3872)
- mention jemalloc in the README (#3877)
- Remove unmaintained "nuke-room-from-db.sh" script (#3888)
-------------------------------------------------------------------
Tue Sep 11 10:03:08 UTC 2018 - fcrozat@suse.com
- Update to version 0.33.4:
* Features:
- Support profile API endpoints on workers (#3659)
- Server notices for resource limit blocking (#3680)
- Allow guests to use /rooms/:roomId/event/:eventId (#3724)
- Add mau_trial_days config param, so that users only get counted as MAU after N days. (#3749)
- Require twisted 17.1 or later (fixes #3741). (#3751)
* Bugfixes:
- Fix error collecting prometheus metrics when run on dedicated thread due to threading concurrency issues (#3722)
- Fix bug where we resent “limit exceeded” server notices repeatedly (#3747)
- Fix bug where we broke sync when using limit_usage_by_mau but hadnt configured server notices (#3753)
- Fix federation_domain_whitelist such that an empty list correctly blocks all outbound federation traffic (#3754)
- Fix tagging of server notice rooms (#3755, #3756)
- Fix admin_uri config variable and error parameter to be admin_contact to match the spec. (#3758)
- Dont return non-LL-member state in incremental sync state blocks (#3760)
- Fix bug in sending presence over federation (#3768)
- Fix bug where preserved threepid user comes to sign up and server is mau blocked (#3777)
-------------------------------------------------------------------
Thu Sep 6 12:24:04 UTC 2018 - fcrozat@suse.com
- Update to version 0.33.3.1:
* SECURITY FIXES:
- Fix an issue where event signatures were not always correctly validated (#3796)
- Fix an issue where server_acls could be circumvented for incoming events (#3796)
-------------------------------------------------------------------
Mon Aug 27 13:30:05 UTC 2018 - fcrozat@suse.com
- Update to version 0.33.3:
* Features:
- Add support for the SNI extension to federation TLS connections. Thanks to @vojeroen! (#3439)
- Add /_media/r0/config (#3184)
- speed up /members API and add at and membership params as per MSC1227 (#3568)
- implement summary block in /sync response as per MSC688 (#3574)
- Add lazy-loading support to /messages as per MSC1227 (#3589)
- Add ability to limit number of monthly active users on the server (#3633)
- Support more federation endpoints on workers (#3653)
- Basic support for room versioning (#3654)
- Ability to disable client/server Synapse via conf toggle (#3655)
- Ability to whitelist specific threepids against monthly active user limiting (#3662)
- Add some metrics for the appservice and federation event sending loops (#3664)
- Where server is disabled, block ability for locked out users to read new messages (#3670)
- set admin uri via config, to be used in error messages where the user should contact the administrator (#3687)
- Synapse's presence functionality can now be disabled with the "use_presence" configuration option. (#3694)
- For resource limit blocked users, prevent writing into rooms (#3708)
* Bugfixes:
- Fix occasional glitches in the synapse_event_persisted_position metric (#3658)
- Fix bug on deleting 3pid when using identity servers that don't support unbind API (#3661)
- Make the tests pass on Twisted < 18.7.0 (#3676)
- Dont ship recaptcha_ajax.js, use it directly from Google (#3677)
- Fixes test_reap_monthly_active_users so it passes under postgres (#3681)
- Fix mau blocking calulation bug on login (#3689)
- Fix missing yield in synapse.storage.monthly_active_users.initialise_reserved_users (#3692)
- Improve HTTP request logging to include all requests (#3700)
- Avoid timing out requests while we are streaming back the response (#3701)
- Support more federation endpoints on workers (#3705, #3713)
- Fix "Starting db txn 'get_all_updated_receipts' from sentinel context" warning (#3710)
- Fix bug where state_cache cache factor ignored environment variables (#3719)
* Deprecations and Removals:
- The Shared-Secret registration method of the legacy v1/register REST endpoint has been removed. For a replacement, please see the admin/register API documentation. (#3703)
- Changes from version 0.33.2:
* Features:
- add support for the lazy_loaded_members filter as per MSC1227 (#2970)
- add support for the include_redundant_members filter param as per MSC1227 (#3331)
- Add metrics to track resource usage by background processes (#3553, #3556, #3604, #3610)
- Add code label to synapse_http_server_response_time_seconds prometheus metric (#3554)
- Add support for client_reader to handle more APIs (#3555, #3597)
- make the /context API filter & lazy-load aware as per MSC1227 (#3567)
- Add ability to limit number of monthly active users on the server (#3630)
- When we fail to join a room over federation, pass the error code back to the client. (#3639)
- Add a new /admin/register API for non-interactively creating users. (#3415)
* Bugfixes:
- Make /directory/list API return 404 for room not found instead of 400. Thanks to @fuzzmz! (#3620)
- Default inviter_display_name to mxid for email invites (#3391)
- Don't generate TURN credentials if no TURN config options are set (#3514)
- Correctly announce deleted devices over federation (#3520)
- Catch failures saving metrics captured by Measure, and instead log the faulty metrics information for further analysis. (#3548)
- Unicode passwords are now normalised before hashing, preventing the instance where two different devices or browsers might send a different UTF-8 sequence for the password. (#3569)
- Fix potential stack overflow and deadlock under heavy load (#3570)
- Respond with M_NOT_FOUND when profiles are not found locally or over federation. Fixes #3585 (#3585)
- Fix failure to persist events over federation under load (#3601)
- Fix updating of cached remote profiles (#3605)
- Fix 'tuple index out of range' error (#3607)
- Only import secrets when available (fix for py < 3.6) (#3626)
-------------------------------------------------------------------
Thu Aug 9 07:04:39 UTC 2018 - okurz@suse.com
- Update to 0.33.1
* Bug Fixes:
* Fix a potential issue where servers could request events for rooms they
have not joined
* Fix a potential issue where users could see events in private rooms
before they joined
-------------------------------------------------------------------
Fri Jul 20 19:32:51 UTC 2018 - okurz@suse.com
- Update to 0.33.0
* Bug Fixes:
* Use more portable syntax in our use of the attrs package, widening the supported versions (#3498)
* Fix queued federation requests being processed in the wrong order (#3533)
* Ensure that erasure requests are correctly honoured for publicly accessible rooms when accessed over federation. (#3546)
* Disable a noisy warning about logcontexts (#3561)
* Features:
* Enforce the specified API for report_event (#3316)
* Include CPU time from database threads in request/block metrics. (#3496, #3501)
* Add CPU metrics for _fetch_event_list (#3497)
* optimisation for /sync (#3505, #3521)
* Optimisation to make handling incoming federation requests more efficient. (#3541)
-------------------------------------------------------------------
Wed Jul 11 04:35:16 UTC 2018 - okurz@suse.com
- Update to 0.32.2
* Bug Fixes:
* Strip access_token from outgoing requests (#3327)
* Redact AS tokens in logs (#3349)
* Fix federation backfill from SQLite servers (#3355)
* Fix event-purge-by-ts admin API (#3363)
* Fix event filtering in get_missing_events handler (#3371)
* Synapse is now stricter regarding accepting events which it cannot
retrieve the prev_events for. (#3456)
* Fix bug where synapse would explode when receiving unicode in HTTP
User-Agent header (#3470)
* Invalidate cache on correct thread to avoid race (#3473)
* Features:
* Add blacklist & whitelist of servers allowed to send events to a
room via ``m.room.server_acl`` event.
* Cache factor override system for specific caches (#3334)
* Add metrics to track appservice transactions (#3344)
* Try to log more helpful info when a sig verification fails (#3372)
* Synapse now uses the best performing JSON encoder/decoder according
to your runtime (simplejson on CPython, stdlib json on PyPy). (#3462)
* Add optional ip_range_whitelist param to AS registration files to
lock AS IP access (#3465)
* Reject invalid server names in federation requests (#3480)
* Reject invalid server names in homeserver.yaml (#3483)
-------------------------------------------------------------------
Tue Jul 10 13:36:51 UTC 2018 - okurz@suse.com
- Update to version 0.31.2:
* Bug Fixes:
* SECURITY UPDATE: Prevent unauthorised users from setting state events in
a room when there is no ``m.room.power_levels`` event in force in the
room. (PR #3397)
- Change to package version format without leading "v"
-------------------------------------------------------------------
Tue Jul 10 11:07:11 UTC 2018 - okurz@suse.com
- Replace deprecated tar_scm by obs_scm
-------------------------------------------------------------------
Sun Jun 10 13:37:54 UTC 2018 - okurz@suse.com
- Update to version v0.31.1:
* Bug Fixes:
* Fix event filtering in get_missing_events handler (PR #3371)
(boo#1096833, CVE-2018-12291)
* Fix metric documentation tables (PR #3341)
* Fix LaterGauge error handling (694968f)
* Fix replication metrics (b7e7fd2)
* Fix federation backfill bugs (PR #3261)
* federation: fix LaterGauge usage (PR #3328) Thanks to @intelfx!
* Fix logcontext resource usage tracking (PR #3258)
* Fix error in handling receipts (PR #3235)
* Stop the transaction cache caching failures (PR #3255)
* Features:
* Let users leave the server notice room after joining (PR #3287)
* Add in flight request metrics (PR #3252)
* Changes:
* Switch to the Python Prometheus library (PR #3256, #3274)
* Cohort analytics (PR #3163, #3241, #3251)
* Add lxml to docker image for web previews (PR #3239) Thanks to @ptman!
* daily user type phone home stats (PR #3264)
* Docs on consent bits (PR #3268)
* Remove users from user directory on deactivate (PR #3277)
* Avoid sending consent notice to guest users (PR #3288)
* disable CPUMetrics if no /proc/self/stat (PR #3299)
* Add private IPv6 addresses to example config for url preview blacklist (PR #3317) Thanks to @thegcat!
* Allow overriding the server_notices user's avatar (PR #3273)
* Support for putting %(consent_uri)s in messages (PR #3271)
* Block attempts to send server notices to remote users (PR #3270)
* Docs on consent bits (PR #3268)
* ConsentResource to gather policy consent from users (PR #3213)
* Infrastructure for a server notices room (PR #3232)
* Send users a server notice about consent (PR #3236)
* Reject attempts to send event before privacy consent is given (PR #3257)
* Don't support limitless pagination (PR #3265)
-------------------------------------------------------------------
Fri May 18 22:00:00 UTC 2018 - cunix@bitmessage.ch
- Update to version v0.29.1:
* Potentially breaking change:
* Make Client-Server API return 401 for invalid token (PR #3161). Thanks to @NotAFile.
* Bug Fixes:
* synapse fails to start under Twisted >= 18.4 (PR #3157)
* Fix a class of logcontext leaks (PR #3170)
* Fix a couple of logcontext leaks in unit tests (PR #3172)
* Fix logcontext leak in media repo (PR #3174)
* Escape label values in prometheus metrics (PR #3175, #3186)
* Fix 'Unhandled Error' logs with Twisted 18.4 (PR #3182) Thanks to @Half-Shot!
* Fix logcontext leaks in rate limiter (PR #3183)
* notifications: Convert next_token to string according to the spec (PR #3190) Thanks to @mujx!
* nuke-room-from-db.sh: fix deletion from search table (PR #3194) Thanks to @rubo77!
* add guard for None on purge_history api (PR #3160) Thanks to @krombel!
* Features:
* Add a Dockerfile for synapse (PR #2846) Thanks to @kaiyou!
* Changes:
* Update docker documentation (PR #3222)
* nuke-room-from-db.sh: added postgresql option and help (PR #2337) Thanks to @rubo77!
* Part user from rooms on account deactivate (PR #3201)
* Make 'unexpected logging context' into warnings (PR #3007)
* Set Server header in SynapseRequest (PR #3208)
* remove duplicates from groups tables (PR #3129)
* Improve exception handling for background processes (PR #3138)
* Add missing consumeErrors to improve exception handling (PR #3139)
* reraise exceptions more carefully (PR #3142)
* Remove redundant call to preserve_fn (PR #3143)
* Trap exceptions thrown within run_in_background (PR #3144)
* Refactor /context to reuse pagination storage functions (PR #3193)
* Refactor recent events func to use pagination func (PR #3195)
* Refactor pagination DB API to return concrete type (PR #3196)
* Refactor get_recent_events_for_room return type (PR #3198)
* Refactor sync APIs to reuse pagination API (PR #3199)
* Remove unused code path from member change DB func (PR #3200)
* Refactor request handling wrappers (PR #3203)
* transaction_id, destination defined twice (PR #3209) Thanks to @damir-manapov!
* Refactor event storage to prepare for changes in state calculations (PR #3141)
* Set Server header in SynapseRequest (PR #3208)
* Use deferred.addTimeout instead of time_bound_deferred (PR #3127, #3178)
* Use run_in_background in preference to preserve_fn (PR #3140)
* Construct HMAC as bytes on py3 (PR #3156) Thanks to @NotAFile!
* run config tests on py3 (PR #3159) Thanks to @NotAFile!
* Open certificate files as bytes (PR #3084) Thanks to @NotAFile!
* Open config file in non-bytes mode (PR #3085) Thanks to @NotAFile!
* Make event properties raise AttributeError instead (PR #3102) Thanks to @NotAFile!
* Use six.moves.urlparse (PR #3108) Thanks to @NotAFile!
* Add py3 tests to tox with folders that work (PR #3145) Thanks to @NotAFile!
* Don't yield in list comprehensions (PR #3150) Thanks to @NotAFile!
* Move more xrange to six (PR #3151) Thanks to @NotAFile!
* make imports local (PR #3152) Thanks to @NotAFile!
* move httplib import to six (PR #3153) Thanks to @NotAFile!
* Replace stringIO imports with six (PR #3154, #3168) Thanks to @NotAFile!
* more bytes strings (PR #3155) Thanks to @NotAFile!
-------------------------------------------------------------------
Mon May 14 20:32:40 UTC 2018 - okurz@suse.com
- Fixed systemd service file installation
- Fixed rpmlint warnings
- Changed to specific "synapse" user and group
-------------------------------------------------------------------
Fri May 4 11:18:46 UTC 2018 - okurz@suse.com
- Update to version v0.28.1:
* SECURITY UPDATE
Clamp the allowed values of event depth received over federation to be
[0, 2^63 - 1]. This mitigates an attack where malicious events
injected with depth = 2^63 - 1 render rooms unusable. Depth is used to
determine the cosmetic ordering of events within a room, and so the ordering
of events in such a room will default to using stream_ordering rather than depth
(topological_ordering).
This is a temporary solution to mitigate abuse in the wild, whilst a long term solution
is being implemented to improve how the depth parameter is used.
Full details at
https://docs.google.com/document/d/1I3fi2S-XnpO45qrpCsowZv8P8dHcNZ4fsBsbOW7KABI/edit#
Pin Twisted to <18.4 until we stop using the private _OpenSSLECCurve API.
* Bug Fixes:
* Return 401 for invalid access_token on logout (PR #2938) Thanks to @dklug!
* Return a 404 rather than a 500 on rejoining empty rooms (PR #3080)
* fix federation_domain_whitelist (PR #3099)
* Avoid creating events with huge numbers of prev_events (PR #3113)
* Reject events which have lots of prev_events (PR #3118)
* Fix quarantine media admin API and search reindex (PR #3130)
* Fix media admin APIs (PR #3134)
* Features:
* Add metrics for event processing lag (PR #3090)
* Add metrics for ResponseCache (PR #3092)
* Changes:
* Synapse on PyPy (PR #2760) Thanks to @Valodim!
* move handling of auto_join_rooms to RegisterHandler (PR #2996) Thanks to @krombel!
* Improve handling of SRV records for federation connections (PR #3016) Thanks to @silkeh!
* Document the behaviour of ResponseCache (PR #3059)
* Preparation for py3 (PR #3061, #3073, #3074, #3075, #3103, #3104, #3106, #3107, #3109, #3110) Thanks to @NotAFile!
* update prometheus dashboard to use new metric names (PR #3069) Thanks to @krombel!
* use python3-compatible prints (PR #3074) Thanks to @NotAFile!
* Send federation events concurrently (PR #3078)
* Limit concurrent event sends for a room (PR #3079)
* Improve R30 stat definition (PR #3086)
* Send events to ASes concurrently (PR #3088)
* Refactor ResponseCache usage (PR #3093)
* Clarify that SRV may not point to a CNAME (PR #3100) Thanks to @silkeh!
* Use str(e) instead of e.message (PR #3103) Thanks to @NotAFile!
* Use six.itervalues in some places (PR #3106) Thanks to @NotAFile!
* Refactor store.have_events (PR #3117)
-------------------------------------------------------------------
Fri Apr 27 06:19:26 UTC 2018 - okurz@suse.com
- Disable web-client for package self-test to get rid of unfulfilled dependency
-------------------------------------------------------------------
Fri Apr 20 18:32:40 UTC 2018 - okurz@suse.com
- Introduce package self-test based on _multibuild
-------------------------------------------------------------------
Mon Apr 16 19:47:23 UTC 2018 - okurz@suse.com
- Update to version v0.27.4:
* Bug fixes:
* URL quote path segments over federation (#3082)
* Add room_id to the response of rooms/{roomId}/join (PR #2986) Thanks to @jplatte!
* Fix replication after switch to simplejson (PR #3015)
* Fix replication after switch to simplejson (PR #3015)
* 404 correctly on missing paths via NoResource (PR #3022)
* Fix error when claiming e2e keys from offline servers (PR #3034)
* fix tests/storage/test_user_directory.py (PR #3042)
* use PUT instead of POST for federating groups/m.join_policy (PR #3070) Thanks to @krombel!
* postgres port script: fix state_groups_pkey error (PR #3072)
* Features:
* Add joinability for groups (PR #3045)
* Implement group join API (PR #3046)
* Add counter metrics for calculating state delta (PR #3033)
* R30 stats (PR #3041)
* Measure time it takes to calculate state group ID (PR #3043)
* Add basic performance statistics to phone home (PR #3044)
* Add response size metrics (PR #3071)
* phone home cache size configurations (PR #3063)
* Changes:
* Update canonicaljson dependency (#3095)
* Add a blurb explaining the main synapse worker (PR #2886) Thanks to @turt2live!
* Replace old style error catching with 'as' keyword (PR #3000) Thanks to @NotAFile!
* Use .iter* to avoid copies in StateHandler (PR #3006)
* Linearize calls to _generate_user_id (PR #3029)
* Remove last usage of ujson (PR #3030)
* Use simplejson throughout (PR #3048)
* Use static JSONEncoders (PR #3049)
* Remove uses of events.content (PR #3060)
* Improve database cache performance (PR #3068)
-------------------------------------------------------------------
Thu Mar 29 05:51:42 UTC 2018 - okurz@suse.com
- Update to version v0.27.2:
* Bug fixes:
* Fix bug which broke TCP replication between workers (PR #3015)
* Fix broken ldap_config config option (PR #2683) Thanks to @seckrv!
* Fix error message when user is not allowed to unban (PR #2761) Thanks to
@turt2live!
* Fix publicised groups GET API (singular) over federation (PR #2772)
* Fix user directory when using user_directory_search_all_users config
option (PR #2803, #2831)
* Fix error on /publicRooms when no rooms exist (PR #2827)
* Fix bug in quarantine_media (PR #2837)
* Fix url_previews when no Content-Type is returned from URL (PR #2845)
* Fix rare race in sync API when joining room (PR #2944)
* Fix slow event search, switch back from GIST to GIN indexes (PR #2769,
#2848)
* Fix bug where an invalid event caused server to stop functioning
correctly, due to parsing and serializing bugs in ujson library.
* Features:
* Add ability for ASes to override message send time (PR #2754)
* Add support for custom storage providers for media repository (PR #2867,
#2777, #2783, #2789, #2791, #2804, #2812, #2814, #2857, #2868, #2767)
* Add purge API features, see docs/admin_api/purge_history_api.rst for
full details (PR #2858, #2867, #2882, #2946, #2962, #2943)
* Add support for whitelisting 3PIDs that users can register. (PR #2813)
* Add /room/{id}/event/{id} API (PR #2766)
* Add an admin API to get all the media in a room (PR #2818) Thanks to
@turt2live!
* Add federation_domain_whitelist option (PR #2820, #2821)
* Changes:
* Continue to factor out processing from main process and into worker
processes. See updated docs/workers.rst (PR #2892 - #2904, #2913, #2920
- #2926, #2947, #2847, #2854, #2872, #2873, #2874, #2928, #2929, #2934,
#2856, #2976 - #2984, #2987 - #2989, #2991 - #2993, #2995, #2784)
* Ensure state cache is used when persisting events (PR #2864, #2871,
#2802, #2835, #2836, #2841, #2842, #2849)
* Change the default config to bind on both IPv4 and IPv6 on all platforms
(PR #2435) Thanks to @silkeh!
* No longer require a specific version of saml2 (PR #2695) Thanks to @okurz!
* Remove verbosity/log_file from generated config (PR #2755)
* Add and improve metrics and logging (PR #2770, #2778, #2785, #2786,
#2787, #2793, #2794, #2795, #2809, #2810, #2833, #2834, #2844, #2965,
#2927, #2975, #2790, #2796, #2838)
* When using synctl with workers, don't start the main synapse
automatically (PR #2774)
* Minor performance improvements (PR #2773, #2792)
* Use a connection pool for non-federation outbound connections (PR #2817)
* Make it possible to run unit tests against postgres (PR #2829)
* Update pynacl dependency to 1.2.1 or higher (PR #2888) Thanks to @bachp!
* Remove ability for AS users to call /events and /sync (PR #2948)
* Use bcrypt.checkpw (PR #2949) Thanks to @krombel!
- Change spec-file to use service downloaded and recompressed file directly
- Remove patch synapse_python_dependencies_allow_higher_versions_of_pysaml2.patch
now included in upstream changes
-------------------------------------------------------------------
Sun Jan 7 10:02:56 UTC 2018 - okurz@suse.com
- Update to version v0.26.0:
* Bug fixes:
* Fix database port script (PR #2673)
* Fix internal server error on login with ldap_auth_provider (PR #2678) Thanks
to @jkolo!
* Fix error on sqlite 3.7 (PR #2697)
* Fix OPTIONS on preview_url (PR #2707)
* Fix error handling on dns lookup (PR #2711)
* Fix wrong avatars when inviting multiple users when creating room (PR #2717)
* Fix 500 when joining matrix-dev (PR #2719)
* Features:
* Add ability for ASes to publicise groups for their users (PR #2686)
* Add all local users to the user_directory and optionally search them (PR
* #2723)
* Add support for custom login types for validating users (PR #2729)
* Changes:
* Update example Prometheus config to new format (PR #2648) Thanks to
@krombel!
* Rename redact_content option to include_content in Push API (PR #2650)
* Declare support for r0.3.0 (PR #2677)
* Improve upserts (PR #2684, #2688, #2689, #2713)
* Improve documentation of workers (PR #2700)
* Improve tracebacks on exceptions (PR #2705)
* Allow guest access to group APIs for reading (PR #2715)
* Support for posting content in federation_client script (PR #2716)
* Delete devices and pushers on logouts etc (PR #2722)
-------------------------------------------------------------------
Mon Nov 20 14:37:18 UTC 2017 - okurz@suse.com
- Update to version v0.25.1:
* Bug fixes:
* Fix login with LDAP and other password provider modules (PR #2678). Thanks to @jkolo!
* Fix port script (PR #2673)
* Fix port script (PR #2577)
* Fix error when running synapse with no logfile (PR #2581)
* Fix UI auth when deleting devices (PR #2591)
* Fix typo when checking if user is invited to group (PR #2599)
* Fix the port script to drop NUL values in all tables (PR #2611)
* Fix appservices being backlogged and not receiving new events due to a bug in
notify_interested_services (PR #2631) Thanks to @xyzz!
* Fix updating rooms avatar/display name when modified by admin (PR #2636)
* Thanks to @farialima!
* Fix bug in state group storage (PR #2649)
* Fix 500 on invalid utf-8 in request (PR #2663)
* Features:
* Add is_public to groups table to allow for private groups (PR #2582)
* Add a route for determining who you are (PR #2668) Thanks to @turt2live!
* Add more features to the password providers (PR #2608, #2610, #2620,
#2622, #2623, #2624, #2626, #2628, #2629)
* Add a hook for custom rest endpoints (PR #2627)
* Add API to update group room visibility (PR #2651)
* Changes:
* Ignore tags when generating URL preview descriptions (PR #2576) Thanks to
@maximevaillancourt!
* Register some /unstable endpoints in /r0 as well (PR #2579) Thanks to @krombel!
* Support /keys/upload on /r0 as well as /unstable (PR #2585)
* Front-end proxy: pass through auth header (PR #2586)
* Allow ASes to deactivate their own users (PR #2589)
* Remove refresh tokens (PR #2613)
* Automatically set default displayname on register (PR #2617)
* Log login requests (PR #2618)
* Always return is_public in the /groups/:group_id/rooms API (PR #2630)
* Avoid no-op media deletes (PR #2637) Thanks to @spantaleev!
* Fix various embarrassing typos around user_directory and add some doc. (PR #2643)
* Return whether a user is an admin within a group (PR #2647)
* Namespace visibility options for groups (PR #2657)
* Downcase UserIDs on registration (PR #2662)
* Cache failures when fetching URL previews (PR #2669)
* Add patch synapse_python_dependencies_allow_higher_versions_of_pysaml2.patch
-------------------------------------------------------------------
Tue Nov 14 12:57:17 UTC 2017 - okurz@suse.com
- Update to version v0.24.1:
* Bug fixes:
* Fix updating group profiles over federation (PR #2567)
* Fix handling SERVFAILs when doing AAAA lookups for federation (PR #2477)
* Fix incompatibility with newer versions of ujson (PR #2483) Thanks to
@jeremycline!
* Fix notification keywords that start/end with non-word chars (PR #2500)
* Fix stack overflow and logcontexts from linearizer (PR #2532)
* Fix 500 error when fields missing from power_levels event (PR #2552)
* Fix 500 error when we get an error handling a PDU (PR #2553)
* Fix regression in performance of syncs (PR #2470)
* Fix caching error in the push evaluator (PR #2332)
* Fix bug where pusherpool didn't start and broke some rooms (PR #2342)
* Fix port script for user directory tables (PR #2375)
* Fix device lists notifications when user rejoins a room (PR #2443, #2449)
* Fix sync to always send down current state events in timeline (PR #2451)
* Fix bug where guest users were incorrectly kicked (PR #2453)
* Fix bug talking to IPv6 only servers using SRV records (PR #2462)
* Fix synapse_port_db failure. Thanks to Pneumaticat! (PR #1904)
* Fix caching to not cache error responses (PR #1913)
* Fix APIs to make kick & ban reasons work (PR #1917)
* Fix bugs in the /keys/changes api (PR #1921)
* Fix bug where users couldn't forget rooms they were banned from (PR #1922)
* Fix issue with long language values in pushers API (PR #1925)
* Fix a race in transaction queue (PR #1930)
* Fix dynamic thumbnailing to preserve aspect ratio. Thanks to jkolo! (PR
#1945)
* Fix device list update to not constantly resync (PR #1964)
* Fix potential for huge memory usage when getting device that have
changed (PR #1969)
* Fix bug where pusher pool didn't start and caused issues when
interacting with some rooms (PR #2342)
* Fix bug with storing registration sessions that caused frequent CPU churn
(PR #2319)
* Fix users not getting notifications when AS listened to that user_id (PR
#2216) Thanks to @slipeer!
* Fix users without push set up not getting notifications after joining rooms
(PR #2236)
* Fix preview url API to trim long descriptions (PR #2243)
* Fix bug where we used cached but unpersisted state group as prev group,
resulting in broken state of restart (PR #2263)
* Fix removing of pushers when using workers (PR #2267)
* Fix CORS headers to allow Authorization header (PR #2285) Thanks to @krombel!
* Fix bug in anonymous usage statistic reporting (PR #2281)
* Fix API to allow clients to upload one-time-keys with new sigs (PR #2206)
* Fix bug where users got pushed for rooms they had muted (PR #2200)
* Fix nuke-room script to work with current schema (PR #1927) Thanks
@zuckschwerdt!
* Fix db port script to not assume postgres tables are in the public schema
(PR #2024) Thanks @jerrykan!
* Fix getting latest device IP for user with no devices (PR #2118)
* Fix rejection of invites to unreachable servers (PR #2145)
* Fix code for reporting old verify keys in synapse (PR #2156)
* Fix invite state to always include all events (PR #2163)
* Fix bug where synapse would always fetch state for any missing event (PR #2170)
* Fix a leak with timed out HTTP connections (PR #2180)
* Fix bug where we didn't time out HTTP requests to ASes (PR #2192)
* Fix joining rooms over federation where not all servers in the room saw the
new server had joined (PR #2094)
* Fix bug where current_state_events renamed to current_state_ids (PR #1849)
* Fix routing loop when fetching remote media (PR #1992)
* Fix current_state_events table to not lie (PR #1996)
* Fix CAS login to handle PartialDownloadError (PR #1997)
* Fix assertion to stop transaction queue getting wedged (PR #2010)
* Fix presence to fallback to last_active_ts if it beats the last sync time.
Thanks @Half-Shot! (PR #2014)
* Fix bug when federation received a PDU while a room join is in progress (PR
#2016)
* Fix resetting state on rejected events (PR #2025)
* Fix installation issues in readme. Thanks @ricco386 (PR #2037)
* Fix caching of remote servers' signature keys (PR #2042)
* Fix some leaking log context (PR #2048, #2049, #2057, #2058)
* Fix rejection of invites not reaching sync (PR #2056)
* Fix bug in handling of incoming device list updates over federation.
* Features:
* Add Group Server (PR #2352, #2363, #2374, #2377, #2378, #2382, #2410, #2426,
#2430, #2454, #2471, #2472, #2544)
* Add support for channel notifications (PR #2501)
* Add basic implementation of backup media store (PR #2538)
* Add config option to auto-join new users to rooms (PR #2545)
* Add a frontend proxy worker (PR #2344)
* Add support for event_id_only push format (PR #2450)
* Add a PoC for filtering spammy events (PR #2456)
* Add a config option to block all room invites (PR #2457)
* Add a user directory API (PR #2252, and many more)
* Add shutdown room API to remove room from local server (PR #2291)
* Add API to quarantine media (PR #2292)
* Add new config option to not send event contents to push servers (PR #2301)
Thanks to @cjdelisle!
* Add per user rate-limiting overrides (PR #2208)
* Add config option to limit maximum number of events requested by ``/sync``
and ``/messages`` (PR #2221) Thanks to @psaavedra!
* Add username availability checker API (PR #2183)
* Add read marker API (PR #2120)
* Add delete_devices API (PR #1993)
* Add phone number registration/login support (PR #1994, #2055)
* Add some administration functionalities. Thanks to morteza-araby! (PR #1784)
* Changes:
* Make the spam checker a module (PR #2474)
* Delete expired url cache data (PR #2478)
* Ignore incoming events for rooms that we have left (PR #2490)
* Allow spam checker to reject invites too (PR #2492)
* Add room creation checks to spam checker (PR #2495)
* Spam checking: add the invitee to user_may_invite (PR #2502)
* Process events from federation for different rooms in parallel (PR #2520)
* Allow error strings from spam checker (PR #2531)
* Improve error handling for missing files in config (PR #2551)
* Make 'affinity' package optional, as it is not supported on some platforms
* Use bcrypt module instead of py-bcrypt (PR #2288) Thanks to @kyrias!
* Improve performance of generating push notifications (PR #2343, #2357, #2365,
#2366, #2371)
* Improve DB performance for device list handling in sync (PR #2362)
* Include a sample prometheus config (PR #2416)
* Document known to work postgres version (PR #2433) Thanks to @ptman!
* Improve performance of storing user IPs (PR #2307, #2308)
* Slightly improve performance of verifying access tokens (PR #2320)
* Slightly improve performance of event persistence (PR #2321)
* Increase default cache factor size from 0.1 to 0.5 (PR #2330)
* Various performance fixes (PR #2177, #2233, #2230, #2238, #2248, #2256,
#2274)
* Deduplicate sync filters (PR #2219) Thanks to @krombel!
* Correct a typo in UPGRADE.rst (PR #2231) Thanks to @aaronraimist!
* Add count of one time keys to sync stream (PR #2237)
* Only store event_auth for state events (PR #2247)
* Store URL cache preview downloads separately (PR #2299)
* Various small performance fixes (PR #2201, #2202, #2224, #2226, #2227, #2228,
#2229)
* Update username availability checker API (PR #2209, #2213)
* When purging, don't de-delta state groups we're about to delete (PR #2214)
* Documentation to check synapse version (PR #2215) Thanks to @hamber-dick!
* Add an index to event_search to speed up purge history API (PR #2218)
* Always mark remotes as up if we receive a signed request from them (PR #2190)
* Enable guest access for the 3pl/3pid APIs (PR #1986)
* Add setting to support TURN for guests (PR #2011)
* Various performance improvements (PR #2075, #2076, #2080, #2083, #2108,
#2158, #2176, #2185)
* Make synctl a bit more user friendly (PR #2078, #2127) Thanks @APwhitehat!
* Replace HTTP replication with TCP replication (PR #2082, #2097, #2098,
#2099, #2103, #2014, #2016, #2115, #2116, #2117)
* Support authenticated SMTP (PR #2102) Thanks @DanielDent!
* Add a counter metric for successfully-sent transactions (PR #2121)
* Propagate errors sensibly from proxied IS requests (PR #2147)
* Add more granular event send metrics (PR #2178)
* Use JSONSchema for validation of filters. Thanks @pik! (PR #1783)
* Reread log config on SIGHUP (PR #1982)
* Speed up public room list (PR #1989)
* Add helpful texts to logger config options (PR #1990)
* Minor ``/sync`` performance improvements. (PR #2002, #2013, #2022)
* Add some debug to help diagnose weird federation issue (PR #2035)
* Correctly limit retries for all federation requests (PR #2050, #2061)
* Don't lock table when persisting new one time keys (PR #2053)
* Reduce some CPU work on DB threads (PR #2054)
* Cache hosts in room (PR #2060)
* Batch sending of device list pokes (PR #2063)
* Speed up persist event path in certain edge cases (PR #2070)
* Reduce database table sizes (PR #1873, #1916, #1923, #1963)
* Update contrib/ to not use syutil. Thanks to andrewshadura! (PR #1907)
* Don't fetch current state when sending an event in common case (PR #1955)
-------------------------------------------------------------------
Tue Nov 14 12:52:53 UTC 2017 - okurz@suse.com
- Update to version v0.24.1+4.632baf79:
* Disallow capital letters in userids
* Allow = in mxids and groupids
* Validate group ids when parsing
* Fix a logcontext leak in the media repo
* Correctly wire in update group profile over federation
* replace 'except:' with 'except Exception:'
* fix vars named `l`
* Bump version and changelog
* Add jitter to validity period of attestations
* Revert "Add jitter to validity period of attestations"
-------------------------------------------------------------------
Tue Jul 4 08:39:45 UTC 2017 - jengelh@inai.de
- Do not suppress errors from useradd procedure.
- Trim description to the essence of the package. It is not
supposed to be a manual or architectural document.
- Remove redundant %clean section. Replace %__-type macro
indirections.
-------------------------------------------------------------------
Thu Jun 29 20:53:00 UTC 2017 - okurz@suse.com
- Prevent conflicts between python2/3 version of packages
-------------------------------------------------------------------
Sun Jun 18 12:05:47 UTC 2017 - okurz@suse.com
- Initial version of matrix-synapse version 0.19.2