Update ghcr.io/element-hq/synapse Docker tag to v1.112.0 #295

Merged
AverageMarcus merged 1 commits from renovate/ghcr.io-element-hq-synapse-1.x into master 2024-07-31 06:58:07 +00:00
Collaborator

This PR contains the following updates:

Package Update Change
ghcr.io/element-hq/synapse (source) minor v1.111.0 -> v1.112.0

Release Notes

element-hq/synapse (ghcr.io/element-hq/synapse)

v1.112.0

Compare Source

Synapse 1.112.0 (2024-07-30)

This security release is to update our locked dependency on Twisted to 24.7.0rc1, which includes a security fix for CVE-2024-41671 / GHSA-c8m8-j448-xjx7: Disordered HTTP pipeline response in twisted.web, again.

Note that this security fix is also available as Synapse 1.111.1, which does not include the rest of the changes in Synapse 1.112.0.

This issue means that, if multiple HTTP requests are pipelined in the same TCP connection, Synapse can send responses to the wrong HTTP request.
If a reverse proxy was configured to use HTTP pipelining, this could result in responses being sent to the wrong user, severely harming confidentiality.

With that said, despite being a high severity issue, we consider it unlikely that Synapse installations will be affected.
The use of HTTP pipelining in this fashion would cause worse performance for clients (request-response latencies would be increased as users' responses would be artificially blocked behind other users' slow requests). Further, Nginx and Haproxy, two common reverse proxies, do not appear to support configuring their upstreams to use HTTP pipelining and thus would not be affected. For both of these reasons, we consider it unlikely that a Synapse deployment would be set up in such a configuration.

Despite that, we cannot rule out that some installations may exist with this unusual setup and so we are releasing this security update today.

pip users: Note that by default, upgrading Synapse using pip will not automatically upgrade Twisted. Please manually install the new version of Twisted using pip install Twisted==24.7.0rc1. Note also that even the --upgrade-strategy=eager flag to pip install -U matrix-synapse will not upgrade Twisted to a patched version because it is only a release candidate at this time.

Internal Changes
  • Upgrade locked dependency on Twisted to 24.7.0rc1. (#​17502)
Synapse 1.112.0rc1 (2024-07-23)

Please note that this release candidate does not include the security dependency update
included in version 1.111.1 as this version was released before 1.111.1.
The same security fix can be found in the full release of 1.112.0.

Features
  • Add to-device extension support to experimental MSC3575 Sliding Sync /sync endpoint. (#​17416)
  • Populate name/avatar fields in experimental MSC3575 Sliding Sync /sync endpoint. (#​17418)
  • Populate heroes and room summary fields (joined_count, invited_count) in experimental MSC3575 Sliding Sync /sync endpoint. (#​17419)
  • Populate is_dm room field in experimental MSC3575 Sliding Sync /sync endpoint. (#​17429)
  • Add room subscriptions to experimental MSC3575 Sliding Sync /sync endpoint. (#​17432)
  • Prepare for authenticated media freeze. (#​17433)
  • Add E2EE extension support to experimental MSC3575 Sliding Sync /sync endpoint. (#​17454)
Bugfixes
  • Add configurable option to always include offline users in presence sync results. Contributed by @​Michael-Hollister. (#​17231)
  • Fix bug in experimental MSC3575 Sliding Sync /sync endpoint when using room type filters and the user has one or more remote invites. (#​17434)
  • Order heroes by stream_ordering as the Matrix specification states (applies to /sync). (#​17435)
  • Fix rare bug where /sync would break for a user when using workers with multiple stream writers. (#​17438)
Improved Documentation
Internal Changes
  • Make sure we always use the right logic for enabling the media repo. (#​17424)
  • Fix argument documentation for method RateLimiter.record_action. (#​17426)
  • Reduce volume of 'Waiting for current token' logs, which were introduced in v1.109.0. (#​17428)
  • Limit concurrent remote downloads to 6 per IP address, and decrement remote downloads without a content-length from the ratelimiter after the download is complete. (#​17439)
  • Remove unnecessary call to resume producing in fake channel. (#​17449)
  • Update experimental MSC3575 Sliding Sync /sync endpoint to bump room when it is created. (#​17453)
  • Speed up generating sliding sync responses. (#​17458)
  • Add cache to get_rooms_for_local_user_where_membership_is to speed up sliding sync. (#​17460)
  • Speed up fetching room keys from backup. (#​17461)
  • Speed up sorting of the room list in sliding sync. (#​17468)
  • Implement handling of $ME as a state key in sliding sync. (#​17469)
Updates to locked dependencies
  • Bump bytes from 1.6.0 to 1.6.1. (#​17441)
  • Bump hiredis from 2.3.2 to 3.0.0. (#​17464)
  • Bump jsonschema from 4.22.0 to 4.23.0. (#​17444)
  • Bump matrix-org/done-action from 2 to 3. (#​17440)
  • Bump mypy from 1.9.0 to 1.10.1. (#​17445)
  • Bump pyopenssl from 24.1.0 to 24.2.1. (#​17465)
  • Bump ruff from 0.5.0 to 0.5.4. (#​17466)
  • Bump sentry-sdk from 2.6.0 to 2.8.0. (#​17456)
  • Bump sentry-sdk from 2.8.0 to 2.10.0. (#​17467)
  • Bump setuptools from 67.6.0 to 70.0.0. (#​17448)
  • Bump twine from 5.1.0 to 5.1.1. (#​17443)
  • Bump types-jsonschema from 4.22.0.20240610 to 4.23.0.20240712. (#​17446)
  • Bump ulid from 1.1.2 to 1.1.3. (#​17442)
  • Bump zipp from 3.15.0 to 3.19.1. (#​17427)

v1.111.1

Compare Source

Synapse 1.111.1 (2024-07-30)

This security release is to update our locked dependency on Twisted to 24.7.0rc1, which includes a security fix for CVE-2024-41671 / GHSA-c8m8-j448-xjx7: Disordered HTTP pipeline response in twisted.web, again.

This issue means that, if multiple HTTP requests are pipelined in the same TCP connection, Synapse can send responses to the wrong HTTP request.
If a reverse proxy was configured to use HTTP pipelining, this could result in responses being sent to the wrong user, severely harming confidentiality.

With that said, despite being a high severity issue, we consider it unlikely that Synapse installations will be affected.
The use of HTTP pipelining in this fashion would cause worse performance for clients (request-response latencies would be increased as users' responses would be artificially blocked behind other users' slow requests). Further, Nginx and Haproxy, two common reverse proxies, do not appear to support configuring their upstreams to use HTTP pipelining and thus would not be affected. For both of these reasons, we consider it unlikely that a Synapse deployment would be set up in such a configuration.

Despite that, we cannot rule out that some installations may exist with this unusual setup and so we are releasing this security update today.

pip users: Note that by default, upgrading Synapse using pip will not automatically upgrade Twisted. Please manually install the new version of Twisted using pip install Twisted==24.7.0rc1. Note also that even the --upgrade-strategy=eager flag to pip install -U matrix-synapse will not upgrade Twisted to a patched version because it is only a release candidate at this time.

Internal Changes
  • Upgrade locked dependency on Twisted to 24.7.0rc1. (#​17502)

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/element-hq/synapse](https://matrix.org/docs/projects/server/synapse) ([source](https://github.com/element-hq/synapse)) | minor | `v1.111.0` -> `v1.112.0` | --- ### Release Notes <details> <summary>element-hq/synapse (ghcr.io/element-hq/synapse)</summary> ### [`v1.112.0`](https://github.com/element-hq/synapse/releases/tag/v1.112.0) [Compare Source](https://github.com/element-hq/synapse/compare/v1.111.1...v1.112.0) ##### Synapse 1.112.0 (2024-07-30) This security release is to update our locked dependency on Twisted to 24.7.0rc1, which includes a security fix for [CVE-2024-41671 / GHSA-c8m8-j448-xjx7: Disordered HTTP pipeline response in twisted.web, again](https://github.com/twisted/twisted/security/advisories/GHSA-c8m8-j448-xjx7). Note that this security fix is also available as **Synapse 1.111.1**, which does not include the rest of the changes in Synapse 1.112.0. This issue means that, if multiple HTTP requests are pipelined in the same TCP connection, Synapse can send responses to the wrong HTTP request. If a reverse proxy was configured to use HTTP pipelining, this could result in responses being sent to the wrong user, severely harming confidentiality. With that said, despite being a high severity issue, **we consider it unlikely that Synapse installations will be affected**. The use of HTTP pipelining in this fashion would cause worse performance for clients (request-response latencies would be increased as users' responses would be artificially blocked behind other users' slow requests). Further, Nginx and Haproxy, two common reverse proxies, do not appear to support configuring their upstreams to use HTTP pipelining and thus would not be affected. For both of these reasons, we consider it unlikely that a Synapse deployment would be set up in such a configuration. Despite that, we cannot rule out that some installations may exist with this unusual setup and so we are releasing this security update today. **pip users:** Note that by default, upgrading Synapse using pip will not automatically upgrade Twisted. **Please manually install the new version of Twisted** using `pip install Twisted==24.7.0rc1`. Note also that even the `--upgrade-strategy=eager` flag to `pip install -U matrix-synapse` will not upgrade Twisted to a patched version because it is only a release candidate at this time. ##### Internal Changes - Upgrade locked dependency on Twisted to 24.7.0rc1. ([#&#8203;17502](https://github.com/element-hq/synapse/issues/17502)) ##### Synapse 1.112.0rc1 (2024-07-23) Please note that this release candidate does not include the security dependency update included in version 1.111.1 as this version was released before 1.111.1. The same security fix can be found in the full release of 1.112.0. ##### Features - Add to-device extension support to experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17416](https://github.com/element-hq/synapse/issues/17416)) - Populate `name`/`avatar` fields in experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17418](https://github.com/element-hq/synapse/issues/17418)) - Populate `heroes` and room summary fields (`joined_count`, `invited_count`) in experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17419](https://github.com/element-hq/synapse/issues/17419)) - Populate `is_dm` room field in experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17429](https://github.com/element-hq/synapse/issues/17429)) - Add room subscriptions to experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17432](https://github.com/element-hq/synapse/issues/17432)) - Prepare for authenticated media freeze. ([#&#8203;17433](https://github.com/element-hq/synapse/issues/17433)) - Add E2EE extension support to experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint. ([#&#8203;17454](https://github.com/element-hq/synapse/issues/17454)) ##### Bugfixes - Add configurable option to always include offline users in presence sync results. Contributed by [@&#8203;Michael-Hollister](https://github.com/Michael-Hollister). ([#&#8203;17231](https://github.com/element-hq/synapse/issues/17231)) - Fix bug in experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint when using room type filters and the user has one or more remote invites. ([#&#8203;17434](https://github.com/element-hq/synapse/issues/17434)) - Order `heroes` by `stream_ordering` as the Matrix specification states (applies to `/sync`). ([#&#8203;17435](https://github.com/element-hq/synapse/issues/17435)) - Fix rare bug where `/sync` would break for a user when using workers with multiple stream writers. ([#&#8203;17438](https://github.com/element-hq/synapse/issues/17438)) ##### Improved Documentation - Update the readme image to have a white background, so that it is readable in dark mode. ([#&#8203;17387](https://github.com/element-hq/synapse/issues/17387)) - Add Red Hat Enterprise Linux and Rocky Linux 8 and 9 installation instructions. ([#&#8203;17423](https://github.com/element-hq/synapse/issues/17423)) - Improve documentation for the [`default_power_level_content_override`](https://element-hq.github.io/synapse/latest/usage/configuration/config_documentation.html#default_power_level_content_override) config option. ([#&#8203;17451](https://github.com/element-hq/synapse/issues/17451)) ##### Internal Changes - Make sure we always use the right logic for enabling the media repo. ([#&#8203;17424](https://github.com/element-hq/synapse/issues/17424)) - Fix argument documentation for method `RateLimiter.record_action`. ([#&#8203;17426](https://github.com/element-hq/synapse/issues/17426)) - Reduce volume of 'Waiting for current token' logs, which were introduced in v1.109.0. ([#&#8203;17428](https://github.com/element-hq/synapse/issues/17428)) - Limit concurrent remote downloads to 6 per IP address, and decrement remote downloads without a content-length from the ratelimiter after the download is complete. ([#&#8203;17439](https://github.com/element-hq/synapse/issues/17439)) - Remove unnecessary call to resume producing in fake channel. ([#&#8203;17449](https://github.com/element-hq/synapse/issues/17449)) - Update experimental [MSC3575](https://github.com/matrix-org/matrix-spec-proposals/pull/3575) Sliding Sync `/sync` endpoint to bump room when it is created. ([#&#8203;17453](https://github.com/element-hq/synapse/issues/17453)) - Speed up generating sliding sync responses. ([#&#8203;17458](https://github.com/element-hq/synapse/issues/17458)) - Add cache to `get_rooms_for_local_user_where_membership_is` to speed up sliding sync. ([#&#8203;17460](https://github.com/element-hq/synapse/issues/17460)) - Speed up fetching room keys from backup. ([#&#8203;17461](https://github.com/element-hq/synapse/issues/17461)) - Speed up sorting of the room list in sliding sync. ([#&#8203;17468](https://github.com/element-hq/synapse/issues/17468)) - Implement handling of `$ME` as a state key in sliding sync. ([#&#8203;17469](https://github.com/element-hq/synapse/issues/17469)) ##### Updates to locked dependencies - Bump bytes from 1.6.0 to 1.6.1. ([#&#8203;17441](https://github.com/element-hq/synapse/issues/17441)) - Bump hiredis from 2.3.2 to 3.0.0. ([#&#8203;17464](https://github.com/element-hq/synapse/issues/17464)) - Bump jsonschema from 4.22.0 to 4.23.0. ([#&#8203;17444](https://github.com/element-hq/synapse/issues/17444)) - Bump matrix-org/done-action from 2 to 3. ([#&#8203;17440](https://github.com/element-hq/synapse/issues/17440)) - Bump mypy from 1.9.0 to 1.10.1. ([#&#8203;17445](https://github.com/element-hq/synapse/issues/17445)) - Bump pyopenssl from 24.1.0 to 24.2.1. ([#&#8203;17465](https://github.com/element-hq/synapse/issues/17465)) - Bump ruff from 0.5.0 to 0.5.4. ([#&#8203;17466](https://github.com/element-hq/synapse/issues/17466)) - Bump sentry-sdk from 2.6.0 to 2.8.0. ([#&#8203;17456](https://github.com/element-hq/synapse/issues/17456)) - Bump sentry-sdk from 2.8.0 to 2.10.0. ([#&#8203;17467](https://github.com/element-hq/synapse/issues/17467)) - Bump setuptools from 67.6.0 to 70.0.0. ([#&#8203;17448](https://github.com/element-hq/synapse/issues/17448)) - Bump twine from 5.1.0 to 5.1.1. ([#&#8203;17443](https://github.com/element-hq/synapse/issues/17443)) - Bump types-jsonschema from 4.22.0.20240610 to 4.23.0.20240712. ([#&#8203;17446](https://github.com/element-hq/synapse/issues/17446)) - Bump ulid from 1.1.2 to 1.1.3. ([#&#8203;17442](https://github.com/element-hq/synapse/issues/17442)) - Bump zipp from 3.15.0 to 3.19.1. ([#&#8203;17427](https://github.com/element-hq/synapse/issues/17427)) ### [`v1.111.1`](https://github.com/element-hq/synapse/releases/tag/v1.111.1) [Compare Source](https://github.com/element-hq/synapse/compare/v1.111.0...v1.111.1) ##### Synapse 1.111.1 (2024-07-30) This security release is to update our locked dependency on Twisted to 24.7.0rc1, which includes a security fix for [CVE-2024-41671 / GHSA-c8m8-j448-xjx7: Disordered HTTP pipeline response in twisted.web, again](https://github.com/twisted/twisted/security/advisories/GHSA-c8m8-j448-xjx7). This issue means that, if multiple HTTP requests are pipelined in the same TCP connection, Synapse can send responses to the wrong HTTP request. If a reverse proxy was configured to use HTTP pipelining, this could result in responses being sent to the wrong user, severely harming confidentiality. With that said, despite being a high severity issue, **we consider it unlikely that Synapse installations will be affected**. The use of HTTP pipelining in this fashion would cause worse performance for clients (request-response latencies would be increased as users' responses would be artificially blocked behind other users' slow requests). Further, Nginx and Haproxy, two common reverse proxies, do not appear to support configuring their upstreams to use HTTP pipelining and thus would not be affected. For both of these reasons, we consider it unlikely that a Synapse deployment would be set up in such a configuration. Despite that, we cannot rule out that some installations may exist with this unusual setup and so we are releasing this security update today. **pip users:** Note that by default, upgrading Synapse using pip will not automatically upgrade Twisted. **Please manually install the new version of Twisted** using `pip install Twisted==24.7.0rc1`. Note also that even the `--upgrade-strategy=eager` flag to `pip install -U matrix-synapse` will not upgrade Twisted to a patched version because it is only a release candidate at this time. ##### Internal Changes - Upgrade locked dependency on Twisted to 24.7.0rc1. ([#&#8203;17502](https://github.com/element-hq/synapse/issues/17502)) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xMy40IiwidXBkYXRlZEluVmVyIjoiMzguMTMuNCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6W119-->
renovate added 1 commit 2024-07-31 03:27:34 +00:00
AverageMarcus merged commit ca3459d377 into master 2024-07-31 06:58:07 +00:00
AverageMarcus deleted branch renovate/ghcr.io-element-hq-synapse-1.x 2024-07-31 06:58:07 +00:00
Sign in to join this conversation.
No reviewers
No Label
No Milestone
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: AverageMarcus/cluster.fun#295
No description provided.