Commit Graph

244 Commits

Author SHA256 Message Date
Dominique Leuenberger
fb84bdfe5d Accepting request 1121497 from network:messaging:matrix
- Update to 1.95.1
  - Security:
    - GHSA-mp92-3jfm-3575 / CVE-2023-43796 — Moderate Severity
      Cached device information of remote users can be queried from
      Synapse. This can be used to enumerate the remote users known
      to a homeserver.

OBS-URL: https://build.opensuse.org/request/show/1121497
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=89
2023-11-01 21:09:47 +00:00
3d5bf2cc09 Accepting request 1121496 from home:darix:apps
- Update to 1.95.1
  - Security:
    - GHSA-mp92-3jfm-3575 / CVE-2023-43796 — Moderate Severity
      Cached device information of remote users can be queried from
      Synapse. This can be used to enumerate the remote users known
      to a homeserver.

OBS-URL: https://build.opensuse.org/request/show/1121496
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=296
2023-10-31 20:07:10 +00:00
Ana Guerrero
ed6636c562 Accepting request 1120125 from network:messaging:matrix
- Update to 1.95.0

OBS-URL: https://build.opensuse.org/request/show/1120125
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=88
2023-10-25 16:03:01 +00:00
2eb079666a Accepting request 1120123 from home:darix:apps
- Update to 1.95.0

OBS-URL: https://build.opensuse.org/request/show/1120123
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=294
2023-10-24 20:00:44 +00:00
Ana Guerrero
85fa09af30 Accepting request 1116889 from network:messaging:matrix
- Update to 1.94.0 (boo#1216126 CVE-2023-45129)
  GHSA-5chr-wjw5-3gq4 / CVE-2023-45129 — Moderate Severity
  A malicious server ACL event can impact performance temporarily
  or permanently leading to a persistent denial of service.
  Homeservers running on a closed federation (which presumably do
  not need to use server ACLs) are not affected.

OBS-URL: https://build.opensuse.org/request/show/1116889
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=87
2023-10-11 21:56:13 +00:00
33f961dbab Accepting request 1116888 from home:darix:apps
- Update to 1.94.0 (boo#1216126 CVE-2023-45129)
  GHSA-5chr-wjw5-3gq4 / CVE-2023-45129 — Moderate Severity
  A malicious server ACL event can impact performance temporarily
  or permanently leading to a persistent denial of service.
  Homeservers running on a closed federation (which presumably do
  not need to use server ACLs) are not affected.

OBS-URL: https://build.opensuse.org/request/show/1116888
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=292
2023-10-11 10:21:26 +00:00
Ana Guerrero
3943aed63b Accepting request 1116700 from network:messaging:matrix
- Update to 1.94.0 (forwarded request 1116682 from darix)

OBS-URL: https://build.opensuse.org/request/show/1116700
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=86
2023-10-10 19:01:18 +00:00
ff899420ed Accepting request 1116682 from home:darix:apps
- Update to 1.94.0

OBS-URL: https://build.opensuse.org/request/show/1116682
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=290
2023-10-10 14:02:02 +00:00
Dominique Leuenberger
5dd7bb3425 Accepting request 1113708 from network:messaging:matrix
- Update to 1.93.0
  The following issues are fixed in 1.93.0 (and RCs).
  GHSA-4f74-84v3-j9q5 / CVE-2023-41335 — Low Severity
  https://github.com/matrix-org/synapse/security/advisories/GHSA-4f74-84v3-j9q5
  Temporary storage of plaintext passwords during password changes.
  GHSA-7565-cq32-vx2x / CVE-2023-42453 — Low Severity
  https://github.com/matrix-org/synapse/security/advisories/GHSA-7565-cq32-vx2x
  Improper validation of receipts allows forged read receipts.
  See the advisories for more details. If you have any questions, email security@matrix.org.

OBS-URL: https://build.opensuse.org/request/show/1113708
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=85
2023-09-27 22:25:02 +00:00
fd426452c9 Accepting request 1113707 from home:darix:apps
- Update to 1.93.0

OBS-URL: https://build.opensuse.org/request/show/1113707
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=288
2023-09-26 17:40:26 +00:00
3548a07d65 Accepting request 1113560 from home:darix:apps
- Update to 1.92.3
  This release does not affect openSUSE as we do not use the intree
  libwebp
  Upstream changes:
  This is again a security update targeted at mitigating
  CVE-2023-4863. It turns out that libwebp is bundled statically in
  Pillow wheels so we need to update this dependency instead of
  libwebp package at the OS level.
  Unlike what was advertised in 1.92.2 changelog this release also
  impacts PyPI wheels and Debian packages from matrix.org.
  We encourage admins to upgrade as soon as possible.
  Internal Changes
  - Pillow 10.0.1 is now mandatory because of libwebp
    CVE-2023-4863, since Pillow provides libwebp in the wheels.
    (#16347)
- bump all the dependencies which are not available in tumbleweed.

- Update to 1.92.2
  Only fix in this is actually changing the upstream docker
  configuration to mitigate the webp security bug. Does not affect
  our package.

- Update to 1.92.1
  - Bugfixes
    - Revert MSC3861 introspection cache, admin impersonation and
      account lock. (#16258)
  - Internal Changes
    - Fix incorrect docstring for Ratelimiter. (#16255)
    - Update the release script to work on macOS. (#16266)
    - Stop building Ubuntu Kinetic since it is EOL and repos seem

OBS-URL: https://build.opensuse.org/request/show/1113560
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=287
2023-09-25 23:13:20 +00:00
Ana Guerrero
863c20feab Accepting request 1109346 from network:messaging:matrix
- Update to 1.91.2

OBS-URL: https://build.opensuse.org/request/show/1109346
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=84
2023-09-07 19:12:54 +00:00
732a56b96c Accepting request 1109344 from home:darix:apps
- Update to 1.91.2

OBS-URL: https://build.opensuse.org/request/show/1109344
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=285
2023-09-06 20:50:53 +00:00
Ana Guerrero
cab2439485 Accepting request 1107016 from network:messaging:matrix
OBS-URL: https://build.opensuse.org/request/show/1107016
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=83
2023-08-28 15:18:26 +00:00
Oliver Kurz
89f349ba3d Accepting request 1104037 from home:darix:apps
- Update to 1.90.0

OBS-URL: https://build.opensuse.org/request/show/1104037
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=283
2023-08-28 12:08:40 +00:00
Dominique Leuenberger
19397dabaa Accepting request 1101105 from network:messaging:matrix
- switch to _multibuild

- Update to 1.88.0
  This release
  - raises the minimum supported version of Python to 3.8, as
    Python 3.7 is now end-of-life, and
  - removes deprecated config options related to worker deployment.
  See the upgrade notes for more information.
  https://github.com/matrix-org/synapse/blob/release-v1.88/docs/upgrade.md#upgrading-to-v1880
  - Features
    - Add not_user_type param to the list accounts admin API.
      (#15844)
  - Bugfixes
    - Revert "Stop writing to column user_id of tables profiles and
      user_filters", which was introduced in Synapse 1.88.0rc1.
      (#15953)
    - Pin pydantic to ^=1.7.4 to avoid backwards-incompatible API
      changes from the 2.0.0 release. Contributed by @PaarthShah.
      (#15862)
    - Correctly resize thumbnails with pillow version >=10.
      (#15876)
  - Improved Documentation
    - Fixed header levels on the Admin API "Users" documentation
      page. Contributed by @sumnerevans at @beeper. (#15852)
    - Remove deprecated worker_replication_host,
      worker_replication_http_port and worker_replication_http_tls
      configuration options. (#15872)
  - Deprecations and Removals
    - Remove deprecated worker_replication_host,
      worker_replication_http_port and worker_replication_http_tls

OBS-URL: https://build.opensuse.org/request/show/1101105
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=82
2023-07-28 20:19:55 +00:00
c926da9e4c OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=281 2023-07-27 16:29:33 +00:00
3500854110 OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=280 2023-07-26 20:57:39 +00:00
ceb1123ef0 Accepting request 1100849 from home:dirkmueller:Factory
- switch to _multibuild

OBS-URL: https://build.opensuse.org/request/show/1100849
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=279
2023-07-26 12:45:04 +00:00
27fc6e051e Accepting request 1099302 from home:darix:apps
- Update to 1.88.0

OBS-URL: https://build.opensuse.org/request/show/1099302
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=278
2023-07-20 12:11:12 +00:00
Oliver Kurz
4a890fecd8 Accepting request 1097605 from home:darix:apps
- Update to 1.87.0

OBS-URL: https://build.opensuse.org/request/show/1097605
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=277
2023-07-13 17:42:37 +00:00
Dominique Leuenberger
a2ecda6c5d Accepting request 1097110 from network:messaging:matrix
- Update to 1.85.2
  - Bugfixes
    - Fix regression where using TLS for HTTP replication between
      workers did not work. Introduced in v1.85.0. (#15746)

- Update to 1.85.1
  Note: this release only fixes a bug that stopped some deployments
  from upgrading to v1.85.0. There is no need to upgrade to v1.85.1
  if successfully running v1.85.0.
  - Bugfixes
    - Fix bug in schema delta that broke upgrades for some
      deployments. Introduced in v1.85.0. (#15738, #15739)

- make use that the pythons define and use_python do not diverge by
  moving them closer to each other.

- Update to 1.85.0
  - Security
    - GHSA-26c5-ppr8-f33p / CVE-2023-32682 — Low Severity It may be
      possible for a deactivated user to login when using uncommon
      configurations. (boo#1212055)
    - GHSA-98px-6486-j7qc / CVE-2023-32683 — Low Severity A
      discovered oEmbed or image URL can bypass the
      url_preview_url_blacklist setting potentially allowing server
      side request forgery or bypassing network policies. Impact is
      limited to IP addresses allowed by the
      url_preview_ip_range_blacklist setting (by default this only
      allows public IPs). (boo#1212054) 
  - Features
    - Improve performance of backfill requests by performing

OBS-URL: https://build.opensuse.org/request/show/1097110
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=81
2023-07-08 20:46:40 +00:00
Aleksa Sarai
54eae36595 Accepting request 1091721 from home:darix:apps
- Update to 1.85.2
  - Bugfixes
    - Fix regression where using TLS for HTTP replication between
      workers did not work. Introduced in v1.85.0. (#15746)

OBS-URL: https://build.opensuse.org/request/show/1091721
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=275
2023-06-21 06:17:28 +00:00
Aleksa Sarai
291f685119 Accepting request 1091284 from home:darix:apps
- Update to 1.85.1
  Note: this release only fixes a bug that stopped some deployments
  from upgrading to v1.85.0. There is no need to upgrade to v1.85.1
  if successfully running v1.85.0.
  - Bugfixes
    - Fix bug in schema delta that broke upgrades for some
      deployments. Introduced in v1.85.0. (#15738, #15739)

OBS-URL: https://build.opensuse.org/request/show/1091284
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=274
2023-06-08 05:34:57 +00:00
Oliver Kurz
3cde411618 Accepting request 1091083 from home:darix:apps
- Update to 1.85.0
  - Security
    - GHSA-26c5-ppr8-f33p / CVE-2023-32682 — Low Severity It may be
      possible for a deactivated user to login when using uncommon
      configurations. (boo#1212055)
    - GHSA-98px-6486-j7qc / CVE-2023-32683 — Low Severity A
      discovered oEmbed or image URL can bypass the
      url_preview_url_blacklist setting potentially allowing server
      side request forgery or bypassing network policies. Impact is
      limited to IP addresses allowed by the
      url_preview_ip_range_blacklist setting (by default this only
      allows public IPs). (boo#1212054)

OBS-URL: https://build.opensuse.org/request/show/1091083
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=273
2023-06-07 07:12:52 +00:00
Oliver Kurz
0429a50e14 Accepting request 1085787 from home:darix:apps
- Update to 1.83.0

OBS-URL: https://build.opensuse.org/request/show/1085787
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=272
2023-05-12 10:16:41 +00:00
Oliver Kurz
6d3303d30b Accepting request 1082745 from home:darix:apps
- Update to 1.82.0

OBS-URL: https://build.opensuse.org/request/show/1082745
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=271
2023-04-26 07:29:53 +00:00
Oliver Kurz
4ea0cb960b Accepting request 1079447 from home:darix:apps
- Update to 1.81.0

OBS-URL: https://build.opensuse.org/request/show/1079447
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=270
2023-04-19 14:40:26 +00:00
fe08a4c542 Accepting request 1075693 from home:darix:apps
- Update to 1.80.0

OBS-URL: https://build.opensuse.org/request/show/1075693
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=269
2023-03-30 21:02:05 +00:00
Dominique Leuenberger
6a94781eb7 Accepting request 1066823 from network:messaging:matrix
- lock matrix-synapse until frozendict can enable python 3.11
  support

OBS-URL: https://build.opensuse.org/request/show/1066823
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=80
2023-02-20 16:46:53 +00:00
11b9c8389e Accepting request 1066822 from home:darix:apps
- lock matrix-synapse until frozendict can enable python 3.11
  support

OBS-URL: https://build.opensuse.org/request/show/1066822
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=267
2023-02-20 12:49:04 +00:00
Dominique Leuenberger
80d0a988aa Accepting request 1065776 from network:messaging:matrix
- Update to 1.77.0

OBS-URL: https://build.opensuse.org/request/show/1065776
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=79
2023-02-14 19:08:14 +00:00
bae58e561a Accepting request 1065775 from home:darix:apps
- Update to 1.77.0

OBS-URL: https://build.opensuse.org/request/show/1065775
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=265
2023-02-14 15:25:26 +00:00
Dominique Leuenberger
1fbb7202e2 Accepting request 1062352 from network:messaging:matrix
- Update to 1.76.0

OBS-URL: https://build.opensuse.org/request/show/1062352
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=78
2023-02-01 15:39:23 +00:00
420a6e4e8a Accepting request 1062351 from home:darix:apps
- Update to 1.76.0

OBS-URL: https://build.opensuse.org/request/show/1062351
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=263
2023-01-31 23:20:59 +00:00
Dominique Leuenberger
fb953aba4a Accepting request 1061962 from network:messaging:matrix
- Update to 1.75.0

OBS-URL: https://build.opensuse.org/request/show/1061962
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=77
2023-01-30 16:10:55 +00:00
98a7a78208 Accepting request 1058976 from home:darix:apps
- Update to 1.75.0

OBS-URL: https://build.opensuse.org/request/show/1058976
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=261
2023-01-30 04:22:48 +00:00
Dominique Leuenberger
8aaedd8051 Accepting request 1046631 from network:messaging:matrix
OBS-URL: https://build.opensuse.org/request/show/1046631
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=76
2023-01-04 16:52:45 +00:00
Oliver Kurz
11e5078ebe Accepting request 1043985 from home:darix:apps
- Update to 1.74.0

OBS-URL: https://build.opensuse.org/request/show/1043985
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=259
2023-01-03 18:30:05 +00:00
Dominique Leuenberger
10490596dd Accepting request 1042241 from network:messaging:matrix
OBS-URL: https://build.opensuse.org/request/show/1042241
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=75
2022-12-12 16:39:36 +00:00
Aleksa Sarai
f3761cffdf Accepting request 1040680 from home:darix:apps
- Update to 1.73.0

OBS-URL: https://build.opensuse.org/request/show/1040680
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=257
2022-12-12 05:14:12 +00:00
Dominique Leuenberger
e207b30df2 Accepting request 1040550 from network:messaging:matrix
OBS-URL: https://build.opensuse.org/request/show/1040550
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=74
2022-12-06 13:24:18 +00:00
Oliver Kurz
231a0ecdd9 Accepting request 1037302 from home:darix:apps
- Update to 1.72.0

OBS-URL: https://build.opensuse.org/request/show/1037302
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=255
2022-12-06 09:24:54 +00:00
Dominique Leuenberger
a68cd62408 Accepting request 1034845 from network:messaging:matrix
- Update to 1.71.0

OBS-URL: https://build.opensuse.org/request/show/1034845
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=73
2022-11-10 13:21:46 +00:00
86780672c2 cleanup unused patch
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=253
2022-11-09 13:08:14 +00:00
e002852642 Accepting request 1034840 from home:darix:apps
- Update to 1.71.0

OBS-URL: https://build.opensuse.org/request/show/1034840
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=252
2022-11-09 13:03:15 +00:00
Oliver Kurz
f6e0b03101 Accepting request 1031982 from home:darix:apps
- Update to 1.70.1
  - Bugfixes
    - Fix a bug introduced in Synapse 1.70.0rc1 where the access
      tokens sent to application services as headers were
      malformed. Application services which were obtaining access
      tokens from query parameters were not affected. (#14301)
    - Fix room creation being rate limited too aggressively since
      Synapse v1.69.0. (#14314)

OBS-URL: https://build.opensuse.org/request/show/1031982
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=251
2022-10-28 15:04:45 +00:00
Oliver Kurz
2573c1f8bf Accepting request 1031328 from home:darix:apps
- Update to 1.70.0

OBS-URL: https://build.opensuse.org/request/show/1031328
OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=250
2022-10-26 12:00:57 +00:00
Dominique Leuenberger
32ab7faf2e Accepting request 1030137 from network:messaging:matrix
- As 14221.patch is modified to skip the parts we dont need
  (changelog snippets) remove the url from the spec file.

- All the shebang line fixing should skip the vendor directory so
  that we do not break the checksum checks in cargo.

- Added https://patch-diff.githubusercontent.com/raw/matrix-org/synapse/pull/14221.patch 
  Same fix for the cache_memory as for url_preview

- python-six is not required
  https://trello.com/c/MO53MocR/143-remove-python3-six

- Update to 1.69.0
  Please note that legacy Prometheus metric names are now
  deprecated and will be removed in Synapse 1.73.0. Server
  administrators should update their dashboards and alerting rules
  to avoid using the deprecated metric names. See the upgrade notes
  for more details.
  - Features
    - Allow application services to set the origin_server_ts of a
      state event by providing the query parameter ts in PUT
      /_matrix/client/r0/rooms/{roomId}/state/{eventType}/{stateKey},
      per MSC3316. Contributed by @lukasdenk. (#11866)
    - Allow server admins to require a manual approval process
      before new accounts can be used (using MSC3866). (#13556)
    - Exponentially backoff from backfilling the same event over
      and over. (#13635, #13936)
    - Add cache invalidation across workers to module API. (#13667,
      #13947)
    - Experimental implementation of MSC3882 to allow an existing

OBS-URL: https://build.opensuse.org/request/show/1030137
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/matrix-synapse?expand=0&rev=72
2022-10-20 14:02:00 +00:00
47d62c35ad - As 14221.patch is modified to skip the parts we dont need
(changelog snippets) remove the url from the spec file.

OBS-URL: https://build.opensuse.org/package/show/network:messaging:matrix/matrix-synapse?expand=0&rev=248
2022-10-20 10:44:50 +00:00