26122 Commits
Author SHA1 Message Date
dependabot[bot] d2b5372ee3 Bump urllib3 from 2.7.0 to 2.8.0 (#20300)
Signed-off-by: dependabot[bot] <support@github.com>
2026-10-01 15:28:27 +00:00
dependabot[bot] cc7b24e5cb Bump tornado from 6.5.7 to 6.5.9 (#20301)
Signed-off-by: dependabot[bot] <support@github.com>
2026-10-01 15:26:16 +00:00
dependabot[bot] a4d1f7b627 Bump the all-github-actions group with 2 updates (#20297)
Bumps the all-github-actions group with 2 updates:
[docker/setup-buildx-action](https://github.com/docker/setup-buildx-action)
and
[docker/build-push-action](https://github.com/docker/build-push-action).

Updates `docker/setup-buildx-action` from 4.3.0 to 4.4.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/docker/setup-buildx-action/releases">docker/setup-buildx-action's
releases</a>.</em></p>
<blockquote>
<h2>v4.4.1</h2>
<ul>
<li>Skip BuildKit image pre-pulls for explicit endpoints by <a
href="https://github.com/crazy-max"><code>@​crazy-max</code></a> in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/624">docker/setup-buildx-action#624</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/docker/setup-buildx-action/compare/v4.4.0...v4.4.1">https://github.com/docker/setup-buildx-action/compare/v4.4.0...v4.4.1</a></p>
<h2>v4.4.0</h2>
<ul>
<li>Use official Buildx releases for cloud driver by <a
href="https://github.com/crazy-max"><code>@​crazy-max</code></a> in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/606">docker/setup-buildx-action#606</a></li>
<li>Pull BuildKit image before builder creation by <a
href="https://github.com/crazy-max"><code>@​crazy-max</code></a> in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/609">docker/setup-buildx-action#609</a></li>
<li>Use shared error helpers for Buildx and Docker commands by <a
href="https://github.com/crazy-max"><code>@​crazy-max</code></a> in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/620">docker/setup-buildx-action#620</a></li>
<li>Bump <code>@​docker/actions-toolkit</code> from 0.95.0 to 0.100.0 in
<a
href="https://redirect.github.com/docker/setup-buildx-action/pull/610">docker/setup-buildx-action#610</a>
<a
href="https://redirect.github.com/docker/setup-buildx-action/pull/618">docker/setup-buildx-action#618</a>
<a
href="https://redirect.github.com/docker/setup-buildx-action/pull/619">docker/setup-buildx-action#619</a></li>
<li>Bump <code>@​humanfs/node</code> from 0.16.7 to 0.16.8 in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/614">docker/setup-buildx-action#614</a></li>
<li>Bump js-yaml from 5.3.0 to 5.4.2 in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/608">docker/setup-buildx-action#608</a>
<a
href="https://redirect.github.com/docker/setup-buildx-action/pull/617">docker/setup-buildx-action#617</a></li>
<li>Bump postcss-selector-parser from 7.1.1 to 7.1.5 in <a
href="https://redirect.github.com/docker/setup-buildx-action/pull/611">docker/setup-buildx-action#611</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/docker/setup-buildx-action/compare/v4.3.0...v4.4.0">https://github.com/docker/setup-buildx-action/compare/v4.3.0...v4.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/f87e5991a6d7451dcb8d9637bfbc97413f497069"><code>f87e599</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/setup-buildx-action/issues/624">#624</a>
from crazy-max/skip-pull-with-endpoint</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/e7002743e035c0054da46ca559364576b2fce022"><code>e700274</code></a>
chore: update generated content</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/3061c919c67ba542099ba309c9181d1900cecc07"><code>3061c91</code></a>
skip BuildKit image pre-pulls for explicit endpoints</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/594f3bf4285d9ea8dc53c9a0c9c4092420091003"><code>594f3bf</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/setup-buildx-action/issues/609">#609</a>
from crazy-max/pull-buildkit-image-before-create</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/bd6e702fc33b636671900d5b5edfab64698c9c25"><code>bd6e702</code></a>
chore: update generated content</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/6268c9da9abbd1309c8a16a75f92a878715c3032"><code>6268c9d</code></a>
pull BuildKit image before builder creation</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/e8235251b82e23c90e6fad50016f0a78b7f28f11"><code>e823525</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/setup-buildx-action/issues/621">#621</a>
from docker/dependabot/github_actions/codeql-actions-...</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/533ed8ed095b0b133ef16fb495aad119524e220d"><code>533ed8e</code></a>
build(deps): bump the codeql-actions group with 2 updates</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/bedaf135699075c88620cd30772b9b6eadc9ba99"><code>bedaf13</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/setup-buildx-action/issues/620">#620</a>
from crazy-max/shared-error-helpers</li>
<li><a
href="https://github.com/docker/setup-buildx-action/commit/d5079fba84d5edd23d25ba7f3045122175ca6ee2"><code>d5079fb</code></a>
chore: update generated content</li>
<li>Additional commits viewable in <a
href="https://github.com/docker/setup-buildx-action/compare/37fe631027851001ddb9b187196cc803df7f5f0e...f87e5991a6d7451dcb8d9637bfbc97413f497069">compare
view</a></li>
</ul>
</details>
<br />

Updates `docker/build-push-action` from 7.3.0 to 7.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/docker/build-push-action/releases">docker/build-push-action's
releases</a>.</em></p>
<blockquote>
<h2>v7.4.0</h2>
<ul>
<li>Use the shared error helper for Buildx commands by <a
href="https://github.com/crazy-max"><code>@​crazy-max</code></a> in <a
href="https://redirect.github.com/docker/build-push-action/pull/1620">docker/build-push-action#1620</a></li>
<li>Prevent workflow command injection in metadata logs by <a
href="https://github.com/crazy-max"><code>@​crazy-max</code></a> in <a
href="https://redirect.github.com/docker/build-push-action/pull/1617">docker/build-push-action#1617</a></li>
<li>Bump <code>@​docker/actions-toolkit</code> from 0.92.0 to 0.100.0 in
<a
href="https://redirect.github.com/docker/build-push-action/pull/1614">docker/build-push-action#1614</a>
<a
href="https://redirect.github.com/docker/build-push-action/pull/1618">docker/build-push-action#1618</a>
<a
href="https://redirect.github.com/docker/build-push-action/pull/1621">docker/build-push-action#1621</a></li>
<li>Bump <code>@​humanfs/node</code> from 0.16.7 to 0.16.8 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1609">docker/build-push-action#1609</a></li>
<li>Bump brace-expansion from 1.1.13 to 1.1.18 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1592">docker/build-push-action#1592</a></li>
<li>Bump csv-parse from 7.0.0 to 7.0.2 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1613">docker/build-push-action#1613</a></li>
<li>Bump js-yaml from 4.3.0 to 4.3.2 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1605">docker/build-push-action#1605</a>
<a
href="https://redirect.github.com/docker/build-push-action/pull/1615">docker/build-push-action#1615</a></li>
<li>Bump nanoid from 3.3.16 to 3.3.18 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1611">docker/build-push-action#1611</a></li>
<li>Bump postcss from 8.5.10 to 8.5.25 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1590">docker/build-push-action#1590</a></li>
<li>Bump postcss-selector-parser from 7.1.1 to 7.1.5 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1606">docker/build-push-action#1606</a></li>
<li>Bump sigstore from 4.1.0 to 4.1.1 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1577">docker/build-push-action#1577</a></li>
<li>Bump undici from 6.27.0 to 6.28.0 in <a
href="https://redirect.github.com/docker/build-push-action/pull/1594">docker/build-push-action#1594</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0">https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/docker/build-push-action/commit/c3c9e263c25d99ce0380d002d59b67737d91b0dc"><code>c3c9e26</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/build-push-action/issues/1621">#1621</a>
from docker/dependabot/npm_and_yarn/docker/actions-t...</li>
<li><a
href="https://github.com/docker/build-push-action/commit/459b6741834dcd35f946352017e7675bd2089d42"><code>459b674</code></a>
[dependabot skip] chore: update generated content</li>
<li><a
href="https://github.com/docker/build-push-action/commit/4dedcb23c91d79c1629bf53ec2c3bcfffef5b34e"><code>4dedcb2</code></a>
chore(deps): Bump <code>@​docker/actions-toolkit</code> from 0.99.0 to
0.100.0</li>
<li><a
href="https://github.com/docker/build-push-action/commit/379bf63a979bd70751945601fa04c50674509952"><code>379bf63</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/build-push-action/issues/1620">#1620</a>
from crazy-max/buildx-error-message</li>
<li><a
href="https://github.com/docker/build-push-action/commit/9877975c9e0b0b661592ff61049069507f9bc2f6"><code>9877975</code></a>
chore: update generated content</li>
<li><a
href="https://github.com/docker/build-push-action/commit/7ed0556ffafb8eb312463411ef0a84a1dfe24d94"><code>7ed0556</code></a>
use the shared Buildx error summary helper</li>
<li><a
href="https://github.com/docker/build-push-action/commit/91670ba5a4df99a24efff8637a78c83fd1b0f6b1"><code>91670ba</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/build-push-action/issues/1618">#1618</a>
from docker/dependabot/npm_and_yarn/docker/actions-t...</li>
<li><a
href="https://github.com/docker/build-push-action/commit/80dbc8614a5c0ce4356740f69179cf829ecdc79a"><code>80dbc86</code></a>
[dependabot skip] chore: update generated content</li>
<li><a
href="https://github.com/docker/build-push-action/commit/50cac3a3b6f55e6015d6483d1dd72a3ecb90d20d"><code>50cac3a</code></a>
chore(deps): Bump <code>@​docker/actions-toolkit</code> from 0.98.0 to
0.99.0</li>
<li><a
href="https://github.com/docker/build-push-action/commit/03b4d6cac0163b44733e1fa60adfd6da560ee4d1"><code>03b4d6c</code></a>
Merge pull request <a
href="https://redirect.github.com/docker/build-push-action/issues/1617">#1617</a>
from crazy-max/fix-metadata-workflow-commands</li>
<li>Additional commits viewable in <a
href="https://github.com/docker/build-push-action/compare/53b7df96c91f9c12dcc8a07bcb9ccacbed38856a...c3c9e263c25d99ce0380d002d59b67737d91b0dc">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 14:44:26 +00:00
Paul Chobert b3b5f3b61d Advertise support for Matrix v1.15 (#20286)
Synapse now implements every item in the Matrix v1.15 changelog (all
ticked in #18731), so it can advertise `v1.15`.

Closes #18731.
2026-09-30 16:17:12 +01:00
dependabot[bot] 81bc4c8c74 Bump pyjwt from 2.13.0 to 2.14.0 (#20291)
Signed-off-by: dependabot[bot] <support@github.com>
2026-09-30 12:51:06 +00:00
Andrew Morgan 32494ab616 Bump cryptography from 46.0.7 to 50.0.1 to resolve several CVEs; bump pyOpenSSL as well (#20253) 2026-09-30 11:24:47 +00:00
Andrew Morgan b3c67110a5 Bump Twisted in poetry.lock from 25.5.0 to 26.4.0 (#20259) 2026-09-29 17:50:55 +00:00
Eric Eastwood c85b1fef9c Prune user_ips less frequently (less stress on the database) (#20285)
Spawning from @Twi1ightSparkle
[spotting](https://matrix.to/#/!SGNQGPGUwtcPBUotTL:matrix.org/$vbqaJ6fJJBzMe1972Z_Ny8euVPWV8IxIS3YWGxP58r0?via=jki.re&via=element.io&via=matrix.org)
a fresh Synapse [running this query every 5
seconds](https://github.com/element-hq/synapse/blob/373fa7f542d86c1dbf82c4ae87c6bec8390e263a/synapse/storage/databases/main/client_ips.py#L440-L441)
which seemed excessive. My initial sniff test thought it was fine
because the more often we run the query, the smaller number of rows we
need to process at a time but @reivilibre brought up that we still have
to scan over all of the dead tuples each time which is a fixed cost
regardless.

Ideally, we'd instead fix the pagination of the query itself to avoid
re-scanning over the tuples. That's probably also a simple change and
I'm mostly just opening this PR to have a place to chuck my worked
example somewhere (mostly for myself). We can always have another
follow-up to do the proper fix.


### `user_ips` dead tuple calculations from `matrix.org`

For `matrix.org`, our autovacuum triggers after the table has
[~5%](https://github.com/matrix-org/matrix-ansible-private/blob/1b623c950e6b4db87f1dd17fa82c83be1b3b58cb/roles/postgres_role/templates/matrix-postgresql.conf.j2#L64-L66)
dead tuples (Postgres normally has a 20% default for
[`autovacuum_vacuum_scale_factor`](https://www.postgresql.org/docs/current/runtime-config-vacuum.html#GUC-AUTOVACUUM-VACUUM-SCALE-FACTOR))

The `user_ips` table on `matrix.org` has 21.8M rows so that means we
have to wait for `(21.8M * 0.05)` = ~1.1M dead rows to accumulate before
the autovacuum kicks in and cleans up all of the dead tuples.

Upper bound napkin math: If we assume that we've reached a steady state
where we prune just as many rows as we insert over the
`user_ips_max_age` time period (defaults to [28
days](https://github.com/element-hq/synapse/blob/373fa7f542d86c1dbf82c4ae87c6bec8390e263a/synapse/config/server.py#L697));
and if the vacuum only ran because of the prune: `21.8M / 28d ~= 778k` a
day -> takes ~1.4 days to accumulate enough dead tuples.

But most of the churn probably comes from updates to the `user_ips`
since every authenticated request updates `user_ips` [every 2
minutes](https://github.com/element-hq/synapse/blob/373fa7f542d86c1dbf82c4ae87c6bec8390e263a/synapse/storage/databases/main/client_ips.py#L52-L55).

And this matches reality:

For actual metrics of `user_ips` on `matrix.org` looking at the
[Postgres
metrics](https://grafana.matrix.org/d/000000009/postgres?orgId=1&var-data_source=000000001)
we have in Prometheus/Grafana:

- ~6.2M updates per day
(`increase(pg_stat_all_tables_n_tup_upd{schemaname!~"pg_.*",
schemaname!~"information_.*", instance=~"$instance"}[1d])`)
- ~792k inserts per day
(`increase(pg_stat_all_tables_n_tup_ins{schemaname!~"pg_.*",
schemaname!~"information_.*", instance=~"$instance"}[1d])`)
     - (inserts don't create dead tuples)
- ~792k deletes per day
(`increase(pg_stat_all_tables_n_tup_del{schemaname!~"pg_.*",
schemaname!~"information_.*", instance=~"$instance"}[1d])`)
     - 9.17 deletes/second

-> ~7M dead tuples per day

So we wait ~3.77 hours to trigger the next autovacuum for this table
`(1.1M * (7M / 24))`. Since the majority of the dead tuples are from
updates, those dead tuples on the other side of the `last_seen` index
and we probably don't have to scan over those for the prune loop. In
between vacuums, we still end up scanning ~124k dead tuples each time we
query on the prune though `(792k * (3.7/24))`.

So even for `matrix.org` levels of busyness and more aggressive
autovacuum, the `5s` interval overkill.

Given 9.17 deletes/second, if we choose a prune loop interval duration
of `60s`, it will pick-up ~550 rows which is under the query `LIMIT` set
(`5000`) with about an order of magnitude head-room to catch-up from
downtime or peak/heavy traffic.
2026-09-29 12:08:35 -05:00
Eric Eastwood 97700856b2 Merge branch 'master' into develop 2026-09-29 11:55:21 -05:00
Andrew Morgan c9b61fc2a3 Stop real threadpool for test DB pool before replacing it with threadless test implementation (#20272) 2026-09-29 16:25:32 +00:00
Eric Eastwood 63dc0cbfe5 1.162.0 v1.162.0 2026-09-29 11:15:31 -05:00
dependabot[bot] 360ab6e002 Bump the all-rust-dependencies group across 1 directory with 6 updates (#20268) 2026-09-29 15:47:19 +01:00
Olivier 'reivilibreandEric Eastwood d1874cdc37 Prevent MSC4354 Sticky Events being sticky when they were redacted prior to persistence. (#20232)
Part of: MSC4354, 
Part of: https://github.com/element-hq/synapse/issues/19641

This PR persists events in redacted form when they already have valid
redactions. That's not directly a sticky events-specific change (and I
feel it makes sense to redact immediately before persistence when we
already have the redaction).

This causes a nice effect which is that the event's stickiness is lost
immediately before persistence, because the `msc4354_sticky` field is
redacted by the redaction algorithm.

---------

Signed-off-by: Olivier 'reivilibre <oliverw@matrix.org>
Co-authored-by: Eric Eastwood <erice@element.io>
2026-09-29 15:22:34 +01:00
Erik JohnstonandClaude Fable 5.1 6472b6a937 Remove Reactor::call_from_thread from the Rust side (#20267)
To use `reactor.callFromThread` we need to take the GIL. However, the
vast majority of use-cases on the Rust side involve using that from
Tokio reactor threads, where we do not want to take the GIL (as it can
potentially block for a long time).

In #20252 we added a pure Rust alternative to `callFromThread`.

`run_python_awaitable` is the last usage of `callFromThread`, and so we
replace it with `dispatch_to_twisted`.

---

The diff is a lot smaller if you hide pure whitespace changes.

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-29 13:41:50 +01:00
Jason Little 0ea6b31f7c Advertise support for Matrix v1.14 (#20137)
As we now do everything from the list of features/changes for v1.13:
#18118
And it appears that v1.14 is already done: #18531
2026-09-29 12:08:40 +01:00
Paul ChobertandOlivier 'reivilibre db618e276d Fix appservice ephemeral read receipts being permanently skipped on large receipt bursts (#20108)
Fixes https://github.com/element-hq/synapse/issues/20096.

Part of https://github.com/element-hq/synapse/issues/18118

The spec requires read receipts to be delivered to interested
application services ([Pushing ephemeral
data](https://spec.matrix.org/v1.19/application-service-api/#pushing-ephemeral-data)):

> If the `receive_ephemeral` settings is enabled in the registration
file, homeservers MUST send ephemeral data that is relevant to the
application service via the transaction API, using the `ephemeral`
property of the request's body.
>
> `m.receipt`: MUST be sent to the application service under the same
rules as regular events, meaning that the application service must have
registered interest in the room itself, or in a user that is in the
room.

Ephemeral data delivery to application services was added in Matrix
v1.13 from
[MSC2409](https://github.com/matrix-org/matrix-spec-proposals/pull/2409)
(see the [v1.13
changelog](https://spec.matrix.org/v1.19/changelog/v1.13/#application-service-api)).

## Problem

When more than 100 read receipts are covered by a single receipt stream
update, only the last 100 are sent to appservices. The rest is
permanently skipped.


## Proposed Fix

- Looping over the receipts in batches of 100 items and updating the
cursor on every iteration
- Keep the fast-forward behavior for new appservices as intended in
https://github.com/matrix-org/synapse/pull/8744

---------

Co-authored-by: Olivier 'reivilibre <oliverw@element.io>
2026-09-29 12:06:15 +01:00
Eric Eastwood 373fa7f542 Ignore suspended users failing when trying to shutdown room (joining new room) (#20283)
Our admin API to delete a room has a weird feature where you can supply
`new_room_user_id` and it will create a new room and join all of the
users to that room:

https://github.com/element-hq/synapse/blob/929e3524d189bf7d3402866b930cebde6bb54892/docs/admin_api/rooms.md#L640-L642

But that room can contain [suspended
users](https://spec.matrix.org/v1.19/client-server-api/#account-suspension)
which are unable to join new rooms. Currently, we use
`logger.exception(...)` for this failure which ends up in Sentry but
since this is probably expected outcome and we shouldn't elevate it to
that level of problem as it's just noise.

Spawning from seeing the error in Sentry,
https://sentry.tools.element.io/organizations/element/issues/11266279/?project=2
```
Traceback (most recent call last):
  File "synapse/handlers/room.py", line 2532, in shutdown_room
    await self.room_member_handler.update_membership(
  File "synapse/handlers/room_member.py", line 675, in update_membership
    result = await self.update_membership_locked(
  File "synapse/handlers/room_member.py", line 794, in update_membership_locked
    raise SynapseError(
SynapseError: 403: Joining rooms while account is suspended is not allowed.
```
2026-09-28 14:21:59 -05:00
Ankit Jha 18c10b8075 Fix 500 error when user-interactive auth requests send a null or non-object auth (#20274)
Fixes #15871

### What was broken

Sending `{"auth": null}` to any endpoint that requires user-interactive
auth (for example `POST /keys/device_signing/upload`, `DELETE
/devices/{deviceId}` or `POST /register`) returned a 500 instead of the
usual 401 with the available flows. A non-object `auth` on endpoints
that do not validate the body with a model (such as `/register`) could
also 500, e.g. `{"auth": ["session"]}`.

### Root cause

`AuthHandler.check_ui_auth` did `clientdict.pop("auth", {})`, so the
`{}` default only applies when the key is missing. An explicit `null`
came through as `None` and the following `"session" in authdict` raised
`TypeError`. `get_session_id` had the same assumption that `auth` is a
dict.

### Pull Request Checklist

* [x] Pull request is based on the develop branch
* [x] Pull request includes a [changelog
file](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#changelog).
* [x] [Code
style](https://element-hq.github.io/synapse/latest/code_style.html) is
correct (run the
[linters](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#run-the-linters))

---------

Signed-off-by: Ankit Jha <ankit.jha@tradomate.one>
2026-09-28 18:36:39 +00:00
Ankit Jha 929e3524d1 fix: reject user creation via the admin API when delegating to MAS (#20241)
Signed-off-by: Ankit Jha <jhaankit373@gmail.com>
Signed-off-by: Ankit Jha <ankit.jha@tradomate.one>
2026-09-28 10:17:37 +00:00
dependabot[bot] a61ce0cfd4 Bump the all-github-actions group across 1 directory with 3 updates (#20269)
Bumps the all-github-actions group with 3 updates in the / directory:
[dtolnay/rust-toolchain](https://github.com/dtolnay/rust-toolchain),
[tailscale/github-action](https://github.com/tailscale/github-action)
and
[marocchino/sticky-pull-request-comment](https://github.com/marocchino/sticky-pull-request-comment).

Updates `dtolnay/rust-toolchain` from
6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 to
02cb101ec7c40f2c49e1d9714d64511d8e1b74de
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/dtolnay/rust-toolchain/commit/02cb101ec7c40f2c49e1d9714d64511d8e1b74de"><code>02cb101</code></a>
Merge pull request 185 from fufesou/feat/force-non-host</li>
<li><a
href="https://github.com/dtolnay/rust-toolchain/commit/b38a663c5df0fd5ac7bb65ded7b02a3f7af3b636"><code>b38a663</code></a>
Pass --force-non-host unconditionally</li>
<li><a
href="https://github.com/dtolnay/rust-toolchain/commit/a4f61a09a512763ecbf6a72db0464f906f59f011"><code>a4f61a0</code></a>
Document rustup non-host opt-in requirement</li>
<li><a
href="https://github.com/dtolnay/rust-toolchain/commit/06b350f08c8596edaf3d95d38686ba934fc4a6a7"><code>06b350f</code></a>
Support force-non-host toolchains</li>
<li><a
href="https://github.com/dtolnay/rust-toolchain/commit/d1031067263f94b142dd6c0ce24c5eb9d02d52a0"><code>d103106</code></a>
Predefine branches up to 1.120</li>
<li><a
href="https://github.com/dtolnay/rust-toolchain/commit/3ea7b2dde9987cecfa88322de1f09983972fc8e9"><code>3ea7b2d</code></a>
Add 1.98.1 patch release</li>
<li>See full diff in <a
href="https://github.com/dtolnay/rust-toolchain/compare/6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772...02cb101ec7c40f2c49e1d9714d64511d8e1b74de">compare
view</a></li>
</ul>
</details>
<br />

Updates `tailscale/github-action` from 4.1.3 to 4.2.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/tailscale/github-action/releases">tailscale/github-action's
releases</a>.</em></p>
<blockquote>
<h2>v4.2.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat: implement log grouping for better output by <a
href="https://github.com/jaxxstorm"><code>@​jaxxstorm</code></a> in <a
href="https://redirect.github.com/tailscale/github-action/pull/304">tailscale/github-action#304</a></li>
<li>fix: reuse stale tailscale.tgz on self-hosted runners by <a
href="https://github.com/TowyTowy"><code>@​TowyTowy</code></a> in <a
href="https://redirect.github.com/tailscale/github-action/pull/305">tailscale/github-action#305</a></li>
<li>Bump typescript from 5.9.3 to 6.0.3 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/tailscale/github-action/pull/298">tailscale/github-action#298</a></li>
<li>Bump actions/setup-node from 6.4.0 to 7.0.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/tailscale/github-action/pull/312">tailscale/github-action#312</a></li>
<li>Bump actions/checkout from 7.0.0 to 7.0.1 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/tailscale/github-action/pull/314">tailscale/github-action#314</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/TowyTowy"><code>@​TowyTowy</code></a>
made their first contribution in <a
href="https://redirect.github.com/tailscale/github-action/pull/305">tailscale/github-action#305</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/tailscale/github-action/compare/v4.1.3...v4.2.0">https://github.com/tailscale/github-action/compare/v4.1.3...v4.2.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/tailscale/github-action/commit/d1b6cd204f8dceda5b3eaad7f1f767be390056cd"><code>d1b6cd2</code></a>
Merge pull request <a
href="https://redirect.github.com/tailscale/github-action/issues/314">#314</a>
from tailscale/dependabot/github_actions/actions/chec...</li>
<li><a
href="https://github.com/tailscale/github-action/commit/f2a4d7820e0a2fa1d2809136f7b5ec81a830d240"><code>f2a4d78</code></a>
Bump actions/checkout from 7.0.0 to 7.0.1</li>
<li><a
href="https://github.com/tailscale/github-action/commit/a122c3446c6d6e2762acc44da35fe65bc3deac1e"><code>a122c34</code></a>
Merge pull request <a
href="https://redirect.github.com/tailscale/github-action/issues/312">#312</a>
from tailscale/dependabot/github_actions/actions/setu...</li>
<li><a
href="https://github.com/tailscale/github-action/commit/55d86933927ed94902b2dd7d32fdfab60c629390"><code>55d8693</code></a>
Bump actions/setup-node from 6.4.0 to 7.0.0</li>
<li><a
href="https://github.com/tailscale/github-action/commit/546937c0d1ff12317e57f889368e81a01fcacb7f"><code>546937c</code></a>
Bump typescript from 5.9.3 to 6.0.3</li>
<li><a
href="https://github.com/tailscale/github-action/commit/0e42fa1ff301a540c9bb9a654695f05e783f05ee"><code>0e42fa1</code></a>
fix: reuse stale tailscale.tgz on self-hosted runners</li>
<li><a
href="https://github.com/tailscale/github-action/commit/508737e1960abaf049b2ca9e6519b8b4291dbf2d"><code>508737e</code></a>
Merge pull request <a
href="https://redirect.github.com/tailscale/github-action/issues/304">#304</a>
from tailscale/log_groups</li>
<li><a
href="https://github.com/tailscale/github-action/commit/5a0d794b306ae171006afad4c14e0ce74d4a8dfe"><code>5a0d794</code></a>
extract logging function into its own class</li>
<li><a
href="https://github.com/tailscale/github-action/commit/ba16990ca09b5f745b03ed05e83b66a722996df7"><code>ba16990</code></a>
catch errors</li>
<li><a
href="https://github.com/tailscale/github-action/commit/191eb01caf1fad37292ad6ffc39136ca24700f9f"><code>191eb01</code></a>
build</li>
<li>Additional commits viewable in <a
href="https://github.com/tailscale/github-action/compare/780049a30b6ff5c378a9e7b389d15ece7a204888...d1b6cd204f8dceda5b3eaad7f1f767be390056cd">compare
view</a></li>
</ul>
</details>
<br />

Updates `marocchino/sticky-pull-request-comment` from
3d7b8546315c63df45a03981d50a43ec19237f80 to
28ad303d6acb4ccfc50f20c0044188e7e294b8c4
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/marocchino/sticky-pull-request-comment/commit/28ad303d6acb4ccfc50f20c0044188e7e294b8c4"><code>28ad303</code></a>
build(deps-dev): Bump <code>@​types/node</code> from 26.1.1 to 26.3.0
(<a
href="https://redirect.github.com/marocchino/sticky-pull-request-comment/issues/1757">#1757</a>)</li>
<li><a
href="https://github.com/marocchino/sticky-pull-request-comment/commit/e17452d56eb060f9ebca915e13b64f051a2fc6aa"><code>e17452d</code></a>
build(deps-dev): Bump vitest from 4.1.10 to 4.1.11 (<a
href="https://redirect.github.com/marocchino/sticky-pull-request-comment/issues/1753">#1753</a>)</li>
<li>See full diff in <a
href="https://github.com/marocchino/sticky-pull-request-comment/compare/3d7b8546315c63df45a03981d50a43ec19237f80...28ad303d6acb4ccfc50f20c0044188e7e294b8c4">compare
view</a></li>
</ul>
</details>
<br />

<details>
<summary>Most Recent Ignore Conditions Applied to This Pull
Request</summary>

| Dependency Name | Ignore Conditions |
| --- | --- |
| dtolnay/rust-toolchain | [> 1.66.0] |
</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-25 13:08:42 +01:00
dependabot[bot] d8fc550190 Bump the all-go-dependencies group in /complement with 2 updates (#20271)
Signed-off-by: dependabot[bot] <support@github.com>
2026-09-25 11:40:11 +00:00
Quentin Gliech d93380a8df Type-check RestServlet.PATTERNS (#20258)
Spawning from
https://github.com/element-hq/synapse/pull/20143#discussion_r4080708454

`RestServlet.register` read `PATTERNS` via `getattr`, so it was typed as
`Any` and mypy never checked subclasses' patterns against what
`HttpServer.register_paths` expects.

This declares the attribute so that classes extending `RestServlet`
provide the right type for the `PATTERNS` attribute.
2026-09-25 13:32:11 +02:00
Erik Johnston 7630492e90 Add metrics for wait_for_stream_token timeouts per lagging stream (#20095)
Add a metric for the number of times we see a stall due to being given a
future token.

This would have caught
https://github.com/element-hq/synapse/issues/20080, where lots of sync
streams got stuck due to a stream not getting replicated correctly.
2026-09-25 12:09:38 +01:00
Andrew Morgan d982869a94 Update in-repo Complement go deps with dependabot (#20270) 2026-09-25 11:03:20 +00:00
Johannes MarbachandAndrew Morgan b8bd6f93a1 Add push rules for MSC4075: MatrixRTC invites and notifications (#20227)
Co-authored-by: Andrew Morgan <1342360+anoadragon453@users.noreply.github.com>
2026-09-25 10:40:24 +00:00
Andrew Morgan 1c122cd825 Configure dependabot to update all non-security dependencies monthly, instead of individual PRs (#20255) 2026-09-25 10:25:10 +00:00
Gagan e2416b3468 Clarify --exists-ok help text (#20263)
## Summary

Clarify the `--exists-ok` command-line help text for
`register_new_matrix_user`.

The previous help text said:

> Do not fail if user already exists.

This could be interpreted as the existing user's account being updated.
The new wording explicitly states that the existing user account will
not be updated.

This also aligns the CLI help text with the existing Debian man page
documentation.

## Issue

Fixes #20112

## Testing

* `git diff --check`
* Reviewed the staged diff to confirm only the intended help-text change
was included.
2026-09-25 11:07:58 +01:00
e863ce7fab Fire deferreds from Rust futures without taking the GIL (#20252)
Tokio tasks currently complete by taking the GIL and calling
`reactor.callFromThread`. Taking the GIL may block for a period of time,
and we do not want that to happen on the tokio reactor threads (as that
can block other work from happening).

To avoid this, we instead add a work queue that we can add to from Rust
without taking the GIL, which is drained by the reactor. We signal to
the Twisted reactor that it should wake up by using a unix socket pair,
which is exactly how `reactor.callFromThread` works.

---

The self-pipe trick is basically where you create a pair of unix sockets
connected to each other. One end is added to the reactor so the reactor
is woken up when there are bytes to read, and when another thread needs
to wake up the reactor it just needs to write a byte into the other unix
socket.

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Andrew Morgan <1342360+anoadragon453@users.noreply.github.com>
2026-09-25 09:49:14 +01:00
Jason Robinson b0d44f9352 Fixes to the profile update stream when a user leaves a room (#20203)
This pull request fixes a few issues with the profile update stream,
when a user leaves a room. This is basically just mimicking what we
already had for when someone leaves a room, and they no longer share any
rooms, but in reverse - ie when we leave a room, and no longer share
rooms with some users. This was missed in the implementation when adding
the profile update stream for legacy and sliding sync.

[Fix missing profile update stream rows on user leaving
room](https://github.com/element-hq/synapse/commit/e953322226731a99718ebe13139b9c5f05ae4b62)

When a user leaves a room, profile update stream rows are generated with
the `LEFT_ROOM` action for each user in the room that no longer shares a
room with the user who left the room.

This also needs to happen in reverse. The user who left the room needs
to have a profile update stream row for each user they no longer share a
room with.

If we don't do this, clients may keep stale data around even after they
don't share a room with a user, which may mean they don't know when to
refetch profiles after re-joining a room with the stale profile data
user.

[Clear out old profile update stream rows when leaving a
room](https://github.com/element-hq/synapse/commit/e7642bf141b098c1eefaf74655e5e7e18415500b)

When we leave a room, ensure profile update stream rows are cleared out
for every user we no longer share a room with. This is the same as what
happens when someone else leaves a room, but in reverse. The only
remaining profile update stream row should be the `LEFT_ROOM` action.

### Pull Request Checklist

<!-- Please read
https://element-hq.github.io/synapse/latest/development/contributing_guide.html
before submitting your pull request -->

* [x] Pull request is based on the develop branch
* [x] Pull request includes a [changelog
file](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#changelog).
The entry should:
- Be a short description of your change which makes sense to users.
"Fixed a bug that prevented receiving messages from other servers."
instead of "Moved X method from `EventStore` to `EventWorkerStore`.".
  - Use markdown where necessary, mostly for `code blocks`.
  - End with either a period (.) or an exclamation mark (!).
  - Start with a capital letter.
- Feel free to credit yourself, by adding a sentence "Contributed by
@github_username." or "Contributed by [Your Name]." to the end of the
entry.
* [x] [Code
style](https://element-hq.github.io/synapse/latest/code_style.html) is
correct (run the
[linters](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#run-the-linters))
2026-09-24 21:22:08 +00:00
Will Hunt b29c3c6764 Omit og:image entirely if the media is quarantined when handling /preview_url (#20211)
This is to prevent the case where URL previews return a MXC that
immediately 404s because the media in question has been quarantined.
This is mostly to help implementations which currently show an ugly
empty preview due to the MXC being sent down, despite being invalid.

### Pull Request Checklist

<!-- Please read
https://element-hq.github.io/synapse/latest/development/contributing_guide.html
before submitting your pull request -->

* [x] Pull request is based on the develop branch
* [x] Pull request includes a [changelog
file](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#changelog).
The entry should:
- Be a short description of your change which makes sense to users.
"Fixed a bug that prevented receiving messages from other servers."
instead of "Moved X method from `EventStore` to `EventWorkerStore`.".
  - Use markdown where necessary, mostly for `code blocks`.
  - End with either a period (.) or an exclamation mark (!).
  - Start with a capital letter.
- Feel free to credit yourself, by adding a sentence "Contributed by
@github_username." or "Contributed by [Your Name]." to the end of the
entry.
* [ ] [Code
style](https://element-hq.github.io/synapse/latest/code_style.html) is
correct (run the
[linters](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#run-the-linters))
2026-09-24 17:48:07 +00:00
Andrew Ferrazzutti 6bdb31e370 Docker: support workers for MSC4140 single lookup (#20262)
Previously, the worker endpoint pattern included only the multi-item
lookup and `/restart`. Adjust the pattern so that it includes the
per-`delay_id` lookup endpoint as well.

Also adjust the worker documentation to use this same endpoint pattern.

Follow-up of #20210
2026-09-24 16:41:59 +01:00
Olivier 'reivilibre 62cb420a0e Send all of a room's MSC4354 Sticky Events down oldschool /sync when a user joins it. (#20233)
Part of: MSC4354 whose experimental feature tracking issue is
https://github.com/element-hq/synapse/issues/19409
Part of: #19662

---------

Signed-off-by: Olivier 'reivilibre <oliverw@matrix.org>
2026-09-24 15:28:06 +01:00
Jason Robinson 8f6f4e03c1 Fix a few readme links regarding ESS (#19070)
Didn't add a changelog, is it needed for this?

### Pull Request Checklist

<!-- Please read
https://element-hq.github.io/synapse/latest/development/contributing_guide.html
before submitting your pull request -->

* [x] Pull request is based on the develop branch
* [x] Pull request includes a [changelog
file](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#changelog).
The entry should:
- Be a short description of your change which makes sense to users.
"Fixed a bug that prevented receiving messages from other servers."
instead of "Moved X method from `EventStore` to `EventWorkerStore`.".
  - Use markdown where necessary, mostly for `code blocks`.
  - End with either a period (.) or an exclamation mark (!).
  - Start with a capital letter.
- Feel free to credit yourself, by adding a sentence "Contributed by
@github_username." or "Contributed by [Your Name]." to the end of the
entry.
* [ ] [Code
style](https://element-hq.github.io/synapse/latest/code_style.html) is
correct (run the
[linters](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#run-the-linters))
2026-09-24 09:58:57 +00:00
64f0590705 MSC4140: cancel a user's delayed events when their account is deactivated (#20247)
[MSC4140](https://github.com/matrix-org/matrix-spec-proposals/blob/main/proposals/4140-delayed-events-futures.md),
"Account deactivation":

> when an account is deactivated, the homeserver MUST cancel that
account's delayed events which have not yet been added to a room's event
DAG. These cancelled records MAY be removed immediately, including their
stored event content, as an exception to the usual finalised-record
retention policy.

Deactivation currently leaves the user's scheduled delayed events,
including their content, in place, and they are still attempted at their
scheduled time:

| Delayed event scheduled by the user | What happens after deactivation
today |
| --- | --- |
| Message or state event, fires after deactivation has made the user
leave the room | The send fails with a 403 (user not in room) and the
record is dropped |
| Message or state event, fires before deactivation has made the user
leave the room (leaving happens room by room in the background) | The
event is sent |
| `m.room.member` join for themselves in a public room | The deactivated
user re-joins the room |

### What changes

- Deactivating an account (client or admin API) removes the user's
unsent delayed events as its first step, and re-arms the send timer for
whatever is scheduled next.
- Deactivation can run on a worker, while the send timer lives on the
main process, so the cancellation goes through a new replication
request.
- A delayed event whose send has already started is left alone, as with
a normal cancel: it is already on its way into the DAG, and the send
path removes its record itself.

Suspension and locking are unchanged.

### After #19038

Today a cancelled delayed event is simply deleted, so this PR deletes
the user's records too. #19038 changes cancellation to keep the record
and mark it as cancelled ("finalised"), so that clients can look up what
happened to a delayed event. Once it has landed, deactivation should
probably finalise the user's records as cancelled the same way, rather
than delete them. The MSC allows either: it permits removing the records
immediately, content included, as an exception to the usual retention of
finalised records, which is worth doing at least when the user asks to
be erased.

### Pull Request Checklist

<!-- Please read
https://element-hq.github.io/synapse/latest/development/contributing_guide.html
before submitting your pull request -->

* [x] Pull request is based on the develop branch
* [x] Pull request includes a [changelog
file](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#changelog).
The entry should:
- Be a short description of your change which makes sense to users.
"Fixed a bug that prevented receiving messages from other servers."
instead of "Moved X method from `EventStore` to `EventWorkerStore`.".
  - Use markdown where necessary, mostly for `code blocks`.
  - End with either a period (.) or an exclamation mark (!).
  - Start with a capital letter.
- Feel free to credit yourself, by adding a sentence "Contributed by
@github_username." or "Contributed by [Your Name]." to the end of the
entry.
* [x] [Code
style](https://element-hq.github.io/synapse/latest/code_style.html) is
correct (run the
[linters](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#run-the-linters))

---------

Co-authored-by: Andrew Ferrazzutti <af_0_af@hotmail.com>
Co-authored-by: Andrew Ferrazzutti <andrewf@element.io>
2026-09-24 10:05:33 +02:00
Paul ChobertandOlivier 'reivilibre' c0b7224e85 Reject limit_profile_requests_to_users_who_share_rooms without require_auth_for_profile_requests (#20231)
As I was working on https://github.com/element-hq/synapse/pull/20218, I
noticed what seemed to be an illegal configuration of synapse.

- `require_auth_for_profile_requests`: blocks profile requests unless
authenticated
- `limit_profile_requests_to_users_who_share_rooms`: blocks profile
requests unless authenticated user share a room with requested user

This, I think, should be an illegal config:

```
require_auth_for_profile_requests = false
limit_profile_requests_to_users_who_share_rooms = true
```

As of now, with such a config the shared-room check is never applied: a
profile can be requested anonymously, and also by an authenticated user
who doesn't share a room.


### Pull Request Checklist

<!-- Please read
https://element-hq.github.io/synapse/latest/development/contributing_guide.html
before submitting your pull request -->

* [x] Pull request is based on the develop branch
* [x] Pull request includes a [changelog
file](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#changelog).
The entry should:
- Be a short description of your change which makes sense to users.
"Fixed a bug that prevented receiving messages from other servers."
instead of "Moved X method from `EventStore` to `EventWorkerStore`.".
  - Use markdown where necessary, mostly for `code blocks`.
  - End with either a period (.) or an exclamation mark (!).
  - Start with a capital letter.
- Feel free to credit yourself, by adding a sentence "Contributed by
@github_username." or "Contributed by [Your Name]." to the end of the
entry.
* [x] [Code
style](https://element-hq.github.io/synapse/latest/code_style.html) is
correct (run the
[linters](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#run-the-linters))

---------

Co-authored-by: Olivier 'reivilibre' <oliverw@element.io>
2026-09-23 16:33:17 +00:00
Olivier 'reivilibre e8987e801e Remove the ability to send state events that are MSC4354 sticky (#20256)
Part of: MSC4354 whose Experimental Feature tracking issue is
https://github.com/element-hq/synapse/issues/19409

Remove the ability to create sticky (MSC4354) state events as a client
This was removed from the MSC in

https://github.com/matrix-org/matrix-spec-proposals/commit/d7d1546d3aa2323ec5d97a50c9f61ab92cd9e14b

---------

Signed-off-by: Olivier 'reivilibre <oliverw@matrix.org>
2026-09-23 17:11:43 +01:00
fbfa7bcfd1 Fix push badge count ignoring a room's notifications when another room's summary is up to date (#20237)
The count of unread notifications is computed in two phases:

1. From the summaries (`event_push_summary`) when those are up to date
with the user's last read receipt
2. Otherwise from counting the push actions (`event_push_actions`) after
that receipt

The problem in this process is that the threads whose summary is up to
date are identified with only their `thread_id`. But all main timelines
share the same `"main"` thread_id, so as soon as one room has an
up-to-date summary, phase 2 skips the main timeline of every room.

The fix identifies the up-to-date summaries with their `(room_id,
thread_id)` pair.

Authored by @sandhose. Found while investigating the
`TestThreadedReceipts` Complement flake (#15517, #18537), but it is a
bug on its own.

### Pull Request Checklist

<!-- Please read
https://element-hq.github.io/synapse/latest/development/contributing_guide.html
before submitting your pull request -->

* [x] Pull request is based on the develop branch
* [x] Pull request includes a [changelog
file](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#changelog).
The entry should:
- Be a short description of your change which makes sense to users.
"Fixed a bug that prevented receiving messages from other servers."
instead of "Moved X method from `EventStore` to `EventWorkerStore`.".
  - Use markdown where necessary, mostly for `code blocks`.
  - End with either a period (.) or an exclamation mark (!).
  - Start with a capital letter.
- Feel free to credit yourself, by adding a sentence "Contributed by
@github_username." or "Contributed by [Your Name]." to the end of the
entry.
* [x] [Code
style](https://element-hq.github.io/synapse/latest/code_style.html) is
correct (run the
[linters](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#run-the-linters))

---------

Co-authored-by: Quentin Gliech <quentingliech@gmail.com>
Co-authored-by: Devon Hudson <devonhudson@librem.one>
2026-09-23 16:08:43 +00:00
Erik Johnston 818f2b25bb Fix error log when writing a large response. (#20246)
We sometimes see a lot of `ERROR` logs like the following:

```
Closing scope Scope<... master.write_bytes_to_request> which is not the currently-active one None
```

This error is generated by `opentracing.Scope` checking that it is the
"active" one. Synapse tracks "active" spans via logcontexts, so this
indirectly asserts that the scope is closed in the context it was opened
in. However, the producer methods are often called from the reactor and
therefore withing the sentinel logcontext, which produces the error
above.

This specifically happens when the producer tries to write large
responses but gets paused, and then later resumes.

The fix is to simply use `Span` directly, rather than scopes. `Span`
does not perform the checks.

I noticed this when deploying #19979, though it is unrelated.
2026-09-23 09:46:50 +01:00
Eric Eastwood 0d7971252b Merge branch 'release-v1.162' into develop 2026-09-22 18:12:51 -05:00
Eric Eastwood 5b3332bcf2 Better align case and canonical "third party rules" spelling v1.162.0rc1 2026-09-22 17:37:07 -05:00
NEVIL ANSON DSOUZAandDevon Hudson 1d7880b9cb Make task scheduler concurrency configurable (#18308) (#20230)
### Summary
Resolves #18308.

Makes the `TaskScheduler`'s maximum concurrent running tasks
configurable via `task_scheduler.max_concurrent_tasks` in the homeserver
configuration and defaults it to `2` (reduced from the previous
hardcoded limit of `5`).

### Motivation
Twisted's `adbapi.ConnectionPool` defaults to 5 database connections
(`cp_max=5`). When the `TaskScheduler` previously executed up to 5 tasks
concurrently, it could exhaust the entire database connection pool,
starving regular API and synchronization requests on smaller homeserver
instances. Lowering the default to 2 preserves at least 3 connections
for foreground requests while allowing concurrent tasks to progress, and
gives administrators the ability to tune the limit according to their
host and connection pool sizing.

### Changes
- Added `TaskSchedulerConfig` (`task_scheduler.max_concurrent_tasks`)
with validation (must be a positive integer) and registered it in
`HomeServerConfig`.
- Updated `TaskScheduler` to enforce the configured concurrency limit
and updated class default to 2.
- Updated config documentation and JSON schema.
- Added config tests in `tests/config/test_task_scheduler_config.py` and
updated unit tests in `tests/util/test_task_scheduler.py`.
- Added newsfragment in `changelog.d/18308.feature`.

---------

Signed-off-by: nevil06 <nevilansondsouza@gmail.com>
Co-authored-by: Devon Hudson <devonhudson@librem.one>
2026-09-22 21:33:59 +00:00
Eric Eastwood 66bfc41864 1.162.0rc1 2026-09-22 13:52:38 -05:00
Eric Eastwood 625b331768 MSC4311: Use full PDU's in stripped state (like invite_room_state) over federation and always include m.room.create event (#19723)
### Background

This PR was originally just trying to remove the flawed [MSC4311](https://github.com/matrix-org/matrix-spec-proposals/pull/4311) partial implementation as client side API's like `/sync` should still use stripped events. But it turns out we were just re-using the client logic for the federation side and things might break if we didn't include the full `m.room.create` event so this PR now introduces MSC4311 support to use full PDU's in the `invite_room_state`/`knock_room_state` in the federation API's.

The flawed implementation was originally introduced in https://github.com/element-hq/synapse/commit/0eb7252a230811e59679cc7e55b92dac26532efc (no PR I assume because part of Hydra security fix) which was part of [Synapse v1.136.0](https://github.com/element-hq/synapse/blob/7530874a1250d6ad975b39582a784c594d29a505/CHANGES.md#synapse-11360-2025-08-12).

Spawning from reviewing https://github.com/element-hq/synapse/pull/19722 and noticing that we have [`TestMSC4311FullCreateEventOnStrippedState`](https://github.com/matrix-org/complement/blob/1e2e12eebc1edb27bbf12108ec849a8254b6ddcd/tests/v12_test.go#L1341-L1376) in Complement which already passes even though that test looks [flawed](https://github.com/matrix-org/complement/pull/791#discussion_r3132468346):

> I think this test is mixing up what [MSC4311](https://github.com/matrix-org/matrix-spec-proposals/pull/4311) proposes. Perhaps these were changes to the MSC that came after?
> 
> For the client API's like `/sync`, it only proposes that `m.room.create` is a required *stripped* state event.
> 
> For the federation API's, alongside requiring `m.room.create`, it also mandates using the full event PDU format for all events in the `invite_room_state`/`knock_room_state` on `m.room.member` events (in `unsigned`)

### What does this PR do?

 1. Always use stripped state for client API's
    1. Remove flawed [MSC4311](https://github.com/matrix-org/matrix-spec-proposals/pull/4311) partial implementation (as explained above)
    1. Sanitize stripped state when we receive events over federation
 1. Use full PDU's when sending `invite_room_state`/`knock_room_state` over federation
 1. Validate PDU's and warn when receiving `invite_room_state`/`knock_room_state` over federation
     1. In the future, we will strictly validate and reject

Complement tests: https://github.com/matrix-org/complement/pull/796

---

Part of https://github.com/element-hq/synapse/issues/19414
2026-09-22 11:57:54 -05:00
Erik Johnston f3ae564877 Report each ID generator's current position as a metric (#20097)
When a stream advances in the database but stops being replicated to a
process, that process's view of the stream freezes. Requests that wait
for it to catch up to a token issued by another worker then time out and
return empty responses indefinitely (see #20080), and nothing exported
said so.

Report `get_current_token` from every ID generator, on every process.
The value is comparable between processes, so a stream that has stopped
reaching one of them shows up as divergence with no client traffic
needed. It is also the position that `wait_for_stream_token` waits on,
so its divergence is the failure itself rather than a proxy for it.

Being a watermark over gapless runs of persisted IDs, it also catches a
single writer of a sharded stream going quiet, which a maximum across
writers would hide behind the writers still being replicated.
2026-09-22 13:16:35 +01:00
dependabot[bot] 7bbf1a5a48 Bump libc from 0.2.174 to 0.2.189 in the patches group (#20249)
Signed-off-by: dependabot[bot] <support@github.com>
2026-09-22 11:38:31 +00:00
Erik JohnstonandClaude Opus 5 9b5697d378 Move per-homeserver Rust state into a RustRuntime object on the HomeServer (#20011)
Previously the tokio runtime was stashed in a hidden attribute on the
reactor object, installed lazily by whichever Rust code first needed it,
and started via `callWhenRunning`.

Instead, we create a `RustRuntime` (accessible via
`HomeServer.get_rust_runtime()`) that holds any per-reactor Rust state,
such as the tokio runtime. It is constructed lazily on use. Rust
consumers (`HttpClient`, `VersionsHandler`, the Python DB pool wrapper)
now receive the runtime or reactor handle explicitly, and the
`reactor.run()` / manual-startup workarounds in tests are no longer
needed.

We also add helper wrappers in Rust for `Reactor` and `HomeServer` that
exposes the needed functionality.

The aim is to allow us to have a Rust-side clock (mainly to get the
current time), that respects the unit test per-reactor time management.

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-21 18:48:37 +01:00
Erik Johnston 218fc91210 Add a cache to state res to cache more cases (#20185)
This is an attempt to better cache the cases where there are a large
number of extremities to resolve over, which keep slightly changing.
This spawns from seeing issues on matrix.org.

We already have a cache over the exact state groups being resolved.
However, we can do better by caching the inputs into state res (i.e. the
conflicted sets), which are more likely to be constant across repeated
state res in a room. We key this cache based on a sha256 hash, on the
assumption that this will never conflict.

Also includes a commit that removes needless copying of the state.
2026-09-21 13:40:31 +01:00
Erik Johnston 26e46786b3 Port LogContext to Rust (#19979)
Ports the logcontext classes to Rust, and gives tokio tasks a captured
logcontext so that work running in (or spawned from) Rust is attributed
to the request that caused it.

1. **Add characterization tests for logcontext error messages and the
filter** — pins the exact `logcontext_error` message shapes, the
abuse-detection code paths and `LoggingContextFilter`'s observable
behaviour, *against the existing Python implementation* (this commit is
green on its own). These are the behavioural contract the port has to
satisfy.
2. **Port `ContextResourceUsage` to a Rust pyclass** — self-contained:
the new `synapse_rust.logcontext` module, the class, its stub and the
re-export.
3. **Move the logcontext storage and `LoggingContext` to Rust** — the
core change; the commit message carries detailed design notes.
Highlights:
- The slot is typed `Option<Py<LoggingContext>>`, with `None`
representing the sentinel. `_Sentinel`/`SENTINEL_CONTEXT` stay pure
Python (unchanged); thin wrappers on
`current_context`/`set_current_context` convert at the boundary, and
pyo3's extraction enforces the type (`TypeError` otherwise).
- The accounting is native: one `getrusage(RUSAGE_THREAD)` read per
switch via libc, inline `stop`/`start` bookkeeping for base
`LoggingContext`s, Python dispatch only for subclasses
(`BackgroundProcessLoggingContext`) so their overrides run. The thread
id comes from `PyThread_get_thread_ident` (the exact
`threading.get_ident()`
     value) without calling into Python.
- The hot paths avoid per-operation allocation: names are `Py<PyString>`
(the per-log-record `str(context)`/`server_name` reads are INCREF-only),
error branches materialise strings only when hit.
4. **Attribute Rust-spawned work to the caller's logcontext** —
`create_deferred` captures the caller's context and scopes it onto the
spawned task via a tokio task-local (`LogContextHandle`);
`current_context()` gives the task-local read precedence, so
`LoggingContextFilter`/`pyo3-log` resolve the right context on worker
threads with no per-record stamping. `run_python_awaitable` restores the
captured context (via a `with_logcontext` helper, the Rust
`PreserveLoggingContext`) around Python called back from Rust, so e.g.
`runInteraction` from the Rust `/versions` handler accounts its DB usage
against the right request. Integration tests exercise both guarantees
through real production code paths.

Follow-up work on top of this (separate PR): porting
`BackgroundProcessLoggingContext` natively and removing further `Py<_>`
indirections. The fact that `BackgroundProcessLoggingContext` is a
subclass is what forces some of the warts in this PR: e.g. having to use
`Py<LoggingContext>` everywhere, etc.

We don't try (yet) to make this pure Rust, instead we see this as simply
maintaining the Python logcontext machinery when crossing, rather than
trying to make a Rust equivalent that can be used by pure Rust
dependencies. We probably do want to do that in future, as well as wire
up e.g. CPU recording on Rust side, but that is unnecessary for now.
2026-09-21 10:00:53 +01:00
Erik Johnston c595869fb7 Add cache to get_partial_filtered_current_state_ids (#20160)
For state filters that ask for concrete types. This allows us to cache
the common case of asking for a specific type/state key.

I noticed a bunch of queries in the jaeger traces that could be cached.
2026-09-18 12:11:09 +01:00
Paul ChobertandErik Johnston 15624be279 Profile endpoint rate limit (#20218)
This provides configurable (via `rc_profile`) rate limits for profile
endpoints:
- `GET /profile/{username}`
- `GET /profile/{username}/{keyName}` including (`displayname` &
`avatar_url`)

### Pull Request Checklist

<!-- Please read
https://element-hq.github.io/synapse/latest/development/contributing_guide.html
before submitting your pull request -->

* [x] Pull request is based on the develop branch
* [x] Pull request includes a [changelog
file](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#changelog).
The entry should:
- Be a short description of your change which makes sense to users.
"Fixed a bug that prevented receiving messages from other servers."
instead of "Moved X method from `EventStore` to `EventWorkerStore`.".
  - Use markdown where necessary, mostly for `code blocks`.
  - End with either a period (.) or an exclamation mark (!).
  - Start with a capital letter.
- Feel free to credit yourself, by adding a sentence "Contributed by
@github_username." or "Contributed by [Your Name]." to the end of the
entry.
* [x] [Code
style](https://element-hq.github.io/synapse/latest/code_style.html) is
correct (run the
[linters](https://element-hq.github.io/synapse/latest/development/contributing_guide.html#run-the-linters))

---------

Co-authored-by: Erik Johnston <erik@matrix.org>
2026-09-18 12:00:45 +01:00