-
-
Notifications
You must be signed in to change notification settings - Fork 15.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
matrix-synapse: 0.27.4 -> 0.28.1 #39922
Conversation
@GrahamcOfBorg test matrix-synapse |
(note that I still could not solve my problems with running the test cases, even on other machines…) |
@GrahamcOfBorg build matrix-synapse |
Success on x86_64-linux (full log) Attempted: matrix-synapse Partial log (click to expand)
|
Success on aarch64-linux (full log) Attempted: matrix-synapse Partial log (click to expand)
|
I just ran the test |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Let's ship this asap. I'll backport to stable.
Security update, backport of NixOS#39922.
@xeji Thanks for the quick response! 🙂 |
@florianjacob Next time please remember to add |
@dotlambda thanks, did not know those prefixes were a thing. Will do! |
Motivation for this change
0.28.1 is an urgent security update: It contains a mitigation for a major denial of service attack that already has been exploited in the wild. For more details, see https://matrix.org/blog/2018/05/01/security-update-synapse-0-28-1/
In my opinion it would make much sense to backport 0.28.1 to stable. Continuing to run vulnerable 0.27.2 out of stable doesn't make much sense anymore, I see no breaking changes from 0.27.2 to 0.28.1, and at least I don't have the time and internal synapse knowledge to backport the temporary workaround to 0.27.2.
For general changelog, see
https://github.com/matrix-org/synapse/blob/master/CHANGES.rst
Things done
build-use-sandbox
innix.conf
on non-NixOS)nix-shell -p nox --run "nox-review wip"
./result/bin/
)