Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
66 commits
Select commit Hold shift + click to select a range
6fabf82
Bump types-opentracing from 2.4.10.6 to 2.4.10.20250622 (#18586)
dependabot[bot] Jun 24, 2025
0c7d991
Fix registering of background updates for split main/state db (#18509)
clokep Jun 25, 2025
0779587
Lift pausing on ratelimited requests to http layer (#18595)
erikjohnston Jun 25, 2025
62b5b0b
Bump reqwest from 0.12.15 to 0.12.20 (#18590)
dependabot[bot] Jun 25, 2025
ec13ed4
Bump docker/setup-buildx-action from 3.10.0 to 3.11.1 (#18587)
dependabot[bot] Jun 25, 2025
99474e7
Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 (#18588)
dependabot[bot] Jun 25, 2025
3807fd4
Bump urllib3 from 2.2.2 to 2.5.0 (#18572)
dependabot[bot] Jun 25, 2025
2f21b27
Bump pyasn1-modules from 0.4.1 to 0.4.2 (#18495)
dependabot[bot] Jun 25, 2025
b088194
Bump docker/build-push-action from 6.17.0 to 6.18.0 (#18497)
dependabot[bot] Jun 25, 2025
b139647
Bump base64 from 0.21.7 to 0.22.1 (#18589)
dependabot[bot] Jun 25, 2025
434e389
Add `federated_user_may_invite` spam checker callback (#18241)
tulir Jun 26, 2025
de29c13
Fix backwards compat for `DirectServeJsonResource` (#18600)
erikjohnston Jun 26, 2025
db710cf
Add `forget_forced_upon_leave` capability as per MSC4267 (#18196)
Johennes Jun 27, 2025
8afea3d
Improve docstring on `simple_upsert_many`. (#18573)
reivilibre Jun 30, 2025
bfb3a6e
Improve performance of device deletion by adding missing index. (#18582)
reivilibre Jun 30, 2025
b35c648
Skip processing policy server events through policy server (#18605)
turt2live Jun 30, 2025
3878699
Speed up device deletion (#18602)
erikjohnston Jun 30, 2025
a2bee2f
Add `via` param to hierarchy enpoint (#18070)
kfiven Jun 30, 2025
2918800
Stop sending or processing the `origin` field in PDUs (#18418)
anoadragon453 Jul 1, 2025
24bcdb3
Merge branch 'master' into develop
sandhose Jul 1, 2025
c17fd94
Fix documentation of the Delete Room Admin API's status field. (#18519)
reivilibre Jul 1, 2025
cc8da2c
Log the room ID we're purging state for (#18625)
erikjohnston Jul 2, 2025
6ddbb03
Raise poetry-core version cap to 2.1.3 (#18575)
V02460 Jul 2, 2025
2f9c9d5
Forbid locked users from using `POST /login` (#18594)
AndrewFerr Jul 2, 2025
8275714
Bump stefanzweifel/git-auto-commit-action from 5.2.0 to 6.0.1 (#18607)
dependabot[bot] Jul 2, 2025
2372f3e
Bump sigstore/cosign-installer from 3.9.0 to 3.9.1 (#18608)
dependabot[bot] Jul 2, 2025
81ca292
Bump types-jsonschema from 4.23.0.20250516 to 4.24.0.20250528 (#18611)
dependabot[bot] Jul 2, 2025
a3ec2d3
Bump pillow from 11.2.1 to 11.3.0 (#18624)
dependabot[bot] Jul 2, 2025
cb4b558
Bump prometheus-client from 0.21.0 to 0.22.1 (#18609)
dependabot[bot] Jul 2, 2025
c210894
Bump treq from 24.9.1 to 25.5.0 (#18610)
dependabot[bot] Jul 2, 2025
717f67f
Bump Swatinem/rust-cache from 2.7.8 to 2.8.0 (#18612)
dependabot[bot] Jul 2, 2025
3bd476e
Bump tokio from 1.45.1 to 1.46.0 (#18628)
dependabot[bot] Jul 2, 2025
87fc518
Bump base64 from 0.21.7 to 0.22.1 (#18629)
dependabot[bot] Jul 2, 2025
e6b8eed
Update Rust in CI to v1.87.0 as well as `dtolnay/rust-toolchain` GitH…
anoadragon453 Jul 2, 2025
dc974fd
Bump sentry-sdk from 2.22.0 to 2.32.0 (#18633)
dependabot[bot] Jul 3, 2025
9d9e140
Bump jsonschema from 4.23.0 to 4.24.0 (#18630)
dependabot[bot] Jul 3, 2025
fb9d737
Bump types-bleach from 6.2.0.20241123 to 6.2.0.20250514 (#18634)
dependabot[bot] Jul 3, 2025
777c3f5
Bump reqwest from 0.12.20 to 0.12.22 (#18627)
dependabot[bot] Jul 3, 2025
ac26805
Bump hiredis from 3.1.0 to 3.2.1 (#18638)
dependabot[bot] Jul 3, 2025
5898271
Bump pydantic from 2.11.4 to 2.11.7 (#18639)
dependabot[bot] Jul 3, 2025
8075c96
Bump mypy-zope from 1.0.11 to 1.0.12 (#18640)
dependabot[bot] Jul 3, 2025
8f4caee
Raise setuptools_rust version cap to 1.11.1 (#18576)
V02460 Jul 3, 2025
0d0f966
Fix GET /_matrix/federation/v1/query/profile response (#18593)
SnackEngineer Jul 3, 2025
832690e
Bump types-pyyaml from 6.0.12.20241230 to 6.0.12.20250516 (#18643)
dependabot[bot] Jul 3, 2025
be4c95b
Replace PyICU with Rust `icu_segmenter` crate (#18553)
anoadragon453 Jul 3, 2025
a06d5ce
Update Cargo.lock (#18646)
anoadragon453 Jul 3, 2025
6c4f852
Bump ruff from 0.11.11 to 0.12.1 (#18645)
dependabot[bot] Jul 3, 2025
b7d54b7
Bump types-setuptools from 75.2.0.20241019 to 80.9.0.20250529 (#18644)
dependabot[bot] Jul 3, 2025
d57a2f7
Bump msgpack from 1.1.0 to 1.1.1 (#18651)
dependabot[bot] Jul 3, 2025
acabece
Bump ijson from 3.3.0 to 3.4.0 (#18650)
dependabot[bot] Jul 3, 2025
4ad93b2
Bump authlib from 1.5.2 to 1.6.0 (#18642)
dependabot[bot] Jul 3, 2025
fc710c4
Bump attrs from 24.2.0 to 25.3.0 (#18649)
dependabot[bot] Jul 3, 2025
6096cb4
Bump phonenumbers from 9.0.2 to 9.0.8 (#18652)
dependabot[bot] Jul 3, 2025
cb0d5a3
Bump typing-extensions from 4.12.2 to 4.14.0 (#18654)
dependabot[bot] Jul 3, 2025
d61b919
Bump setuptools-rust from 1.10.2 to 1.11.1 (#18655)
dependabot[bot] Jul 4, 2025
4a7b166
Bump ruff from 0.12.1 to 0.12.2 (#18657)
dependabot[bot] Jul 4, 2025
49e46b8
Bump types-psycopg2 from 2.9.21.20250318 to 2.9.21.20250516 (#18658)
dependabot[bot] Jul 4, 2025
616ada3
Bump tokio from 1.46.0 to 1.46.1 (#18667)
dependabot[bot] Jul 7, 2025
5722070
Bump typing-extensions from 4.14.0 to 4.14.1 (#18668)
dependabot[bot] Jul 7, 2025
9b86458
Speed up the building of Docker images using ARM CI workers (#18620)
sandhose Jul 8, 2025
b8ad9bf
Add `.zed/` to `.gitignore` (#18623)
anoadragon453 Jul 8, 2025
f8a7872
Use native arm runners for building wheels (#18618)
sandhose Jul 8, 2025
5c2765b
1.134.0rc1
anoadragon453 Jul 9, 2025
60be549
1.134.0
erikjohnston Jul 15, 2025
d3e3836
Famedly v1.134
jason-famedly Jul 18, 2025
26b360d
Update poetry.lock
jason-famedly Jul 18, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
140 changes: 98 additions & 42 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ name: Build docker images
on:
push:
tags: ["v*"]
branches: [ master, main, develop ]
branches: [master, main, develop]
workflow_dispatch:

permissions:
Expand All @@ -14,23 +14,21 @@ permissions:
id-token: write # needed for signing the images with GitHub OIDC Token
jobs:
build:
runs-on: ubuntu-22.04
name: Build and push image for ${{ matrix.platform }}
runs-on: ${{ matrix.runs_on }}
strategy:
matrix:
include:
- platform: linux/amd64
runs_on: ubuntu-24.04
suffix: linux-amd64
- platform: linux/arm64
runs_on: ubuntu-24.04-arm
suffix: linux-arm64
steps:
- name: Set up QEMU
id: qemu
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
platforms: arm64

- name: Set up Docker Buildx
id: buildx
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3.10.0

- name: Inspect builder
run: docker buildx inspect

- name: Install Cosign
uses: sigstore/cosign-installer@3454372f43399081ed03b604cb2d021dabca52bb # v3.8.2
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1

- name: Checkout repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
Expand All @@ -55,45 +53,103 @@ jobs:
username: ${{ github.repository_owner }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Calculate docker image tag
id: set-tag
uses: docker/metadata-action@902fa8ec7d6ecbf8d84d538b9b233a880e428804 # v5.7.0
- name: Build and push by digest
id: build
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
with:
images: |
push: true
labels: |
gitsha1=${{ github.sha }}
org.opencontainers.image.version=${{ env.SYNAPSE_VERSION }}
tags: |
docker.io/matrixdotorg/synapse
ghcr.io/element-hq/synapse
file: "docker/Dockerfile"
platforms: ${{ matrix.platform }}
outputs: type=image,push-by-digest=true,name-canonical=true,push=true

- name: Export digest
run: |
mkdir -p ${{ runner.temp }}/digests
digest="${{ steps.build.outputs.digest }}"
touch "${{ runner.temp }}/digests/${digest#sha256:}"

- name: Upload digest
uses: actions/upload-artifact@v4
with:
name: digests-${{ matrix.suffix }}
path: ${{ runner.temp }}/digests/*
if-no-files-found: error
retention-days: 1

merge:
name: Push merged images to ${{ matrix.repository }}
runs-on: ubuntu-latest
strategy:
matrix:
repository:
- docker.io/matrixdotorg/synapse
- ghcr.io/element-hq/synapse

needs:
- build
steps:
- name: Download digests
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
path: ${{ runner.temp }}/digests
pattern: digests-*
merge-multiple: true

- name: Log in to DockerHub
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
if: ${{ startsWith(matrix.repository, 'docker.io') }}
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}

- name: Log in to GHCR
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
if: ${{ startsWith(matrix.repository, 'ghcr.io') }}
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1

- name: Install Cosign
uses: sigstore/cosign-installer@398d4b0eeef1380460a10c8013a76f728fb906ac # v3.9.1

- name: Calculate docker image tag
uses: docker/metadata-action@902fa8ec7d6ecbf8d84d538b9b233a880e428804 # v5.7.0
with:
images: ${{ matrix.repository }}
flavor: |
latest=false
tags: |
type=raw,value=develop,enable=${{ github.ref == 'refs/heads/develop' }}
type=raw,value=latest,enable=${{ github.ref == 'refs/heads/master' }}
type=raw,value=latest,enable=${{ github.ref == 'refs/heads/main' }}
type=pep440,pattern={{raw}}
type=sha

- name: Build and push all platforms
id: build-and-push
uses: docker/build-push-action@1dc73863535b631f98b2378be8619f83b136f4a0 # v6.17.0
with:
push: true
labels: |
gitsha1=${{ github.sha }}
org.opencontainers.image.version=${{ env.SYNAPSE_VERSION }}
tags: "${{ steps.set-tag.outputs.tags }}"
file: "docker/Dockerfile"
platforms: linux/amd64,linux/arm64

# arm64 builds OOM without the git fetch setting. c.f.
# https://github.com/rust-lang/cargo/issues/10583
build-args: |
CARGO_NET_GIT_FETCH_WITH_CLI=true
- name: Create manifest list and push
working-directory: ${{ runner.temp }}/digests
env:
REPOSITORY: ${{ matrix.repository }}
run: |
docker buildx imagetools create $(jq -cr '.tags | map("-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \
$(printf "$REPOSITORY@sha256:%s " *)

- name: Sign the images with GitHub OIDC Token
- name: Sign each manifest
env:
DIGEST: ${{ steps.build-and-push.outputs.digest }}
TAGS: ${{ steps.set-tag.outputs.tags }}
REPOSITORY: ${{ matrix.repository }}
run: |
images=""
for tag in ${TAGS}; do
images+="${tag}@${DIGEST} "
DIGESTS=""
for TAG in $(echo "$DOCKER_METADATA_OUTPUT_JSON" | jq -r '.tags[]'); do
DIGEST="$(docker buildx imagetools inspect $TAG --format '{{json .Manifest}}' | jq -r '.digest')"
DIGESTS="$DIGESTS $REPOSITORY@$DIGEST"
done
cosign sign --yes ${images}
cosign sign --yes $DIGESTS
15 changes: 9 additions & 6 deletions .github/workflows/fix_lint.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,11 @@ name: Attempt to automatically fix linting errors
on:
workflow_dispatch:

env:
# We use nightly so that `fmt` correctly groups together imports, and
# clippy correctly fixes up the benchmarks.
RUST_VERSION: nightly-2025-06-24

jobs:
fixup:
name: Fix up
Expand All @@ -16,13 +21,11 @@ jobs:
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- name: Install Rust
uses: dtolnay/rust-toolchain@56f84321dbccf38fb67ce29ab63e4754056677e0 # master (rust 1.85.1)
uses: dtolnay/rust-toolchain@b3b07ba8b418998c39fb20f53e8b695cdcc8de1b # master
with:
# We use nightly so that `fmt` correctly groups together imports, and
# clippy correctly fixes up the benchmarks.
toolchain: nightly-2022-12-01
toolchain: ${{ env.RUST_VERSION }}
components: clippy, rustfmt
- uses: Swatinem/rust-cache@9d47c6ad4b02e050fd481d890b2ea34778fd09d6 # v2.7.8
- uses: Swatinem/rust-cache@98c8021b550208e191a6a3145459bfc9fb29c4c0 # v2.8.0

- name: Setup Poetry
uses: matrix-org/setup-python-poetry@5bbf6603c5c930615ec8a29f1b5d7d258d905aa4 # v2.0.0
Expand All @@ -44,6 +47,6 @@ jobs:
- run: cargo fmt
continue-on-error: true

- uses: stefanzweifel/git-auto-commit-action@b863ae1933cb653a53c021fe36dbb774e1fb9403 # v5.2.0
- uses: stefanzweifel/git-auto-commit-action@778341af668090896ca464160c2def5d1d1a3eb0 # v6.0.1
with:
commit_message: "Attempt to fix linting"
21 changes: 15 additions & 6 deletions .github/workflows/latest_deps.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

env:
RUST_VERSION: 1.87.0

jobs:
check_repo:
# Prevent this workflow from running on any fork of Synapse other than element-hq/synapse, as it is
Expand All @@ -41,8 +44,10 @@ jobs:
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: Install Rust
uses: dtolnay/rust-toolchain@fcf085fcb4b4b8f63f96906cd713eb52181b5ea4 # stable (rust 1.85.1)
- uses: Swatinem/rust-cache@9d47c6ad4b02e050fd481d890b2ea34778fd09d6 # v2.7.8
uses: dtolnay/rust-toolchain@b3b07ba8b418998c39fb20f53e8b695cdcc8de1b # master
with:
toolchain: ${{ env.RUST_VERSION }}
- uses: Swatinem/rust-cache@98c8021b550208e191a6a3145459bfc9fb29c4c0 # v2.8.0

# The dev dependencies aren't exposed in the wheel metadata (at least with current
# poetry-core versions), so we install with poetry.
Expand Down Expand Up @@ -75,8 +80,10 @@ jobs:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- name: Install Rust
uses: dtolnay/rust-toolchain@fcf085fcb4b4b8f63f96906cd713eb52181b5ea4 # stable (rust 1.85.1)
- uses: Swatinem/rust-cache@9d47c6ad4b02e050fd481d890b2ea34778fd09d6 # v2.7.8
uses: dtolnay/rust-toolchain@b3b07ba8b418998c39fb20f53e8b695cdcc8de1b # master
with:
toolchain: ${{ env.RUST_VERSION }}
- uses: Swatinem/rust-cache@98c8021b550208e191a6a3145459bfc9fb29c4c0 # v2.8.0

- run: sudo apt-get -qq install xmlsec1
- name: Set up PostgreSQL ${{ matrix.postgres-version }}
Expand Down Expand Up @@ -148,8 +155,10 @@ jobs:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- name: Install Rust
uses: dtolnay/rust-toolchain@fcf085fcb4b4b8f63f96906cd713eb52181b5ea4 # stable (rust 1.85.1)
- uses: Swatinem/rust-cache@9d47c6ad4b02e050fd481d890b2ea34778fd09d6 # v2.7.8
uses: dtolnay/rust-toolchain@b3b07ba8b418998c39fb20f53e8b695cdcc8de1b # master
with:
toolchain: ${{ env.RUST_VERSION }}
- uses: Swatinem/rust-cache@98c8021b550208e191a6a3145459bfc9fb29c4c0 # v2.8.0

- name: Ensure sytest runs `pip install`
# Delete the lockfile so sytest will `pip install` rather than `poetry install`
Expand Down
42 changes: 15 additions & 27 deletions .github/workflows/release-artifacts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ jobs:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: '3.x'
python-version: "3.x"
- id: set-distros
run: |
# if we're running from a tag, get the full list of distros; otherwise just use debian:sid
Expand Down Expand Up @@ -61,7 +61,7 @@ jobs:

- name: Set up Docker Buildx
id: buildx
uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3.10.0
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
with:
install: true

Expand All @@ -76,7 +76,7 @@ jobs:
- name: Set up python
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: '3.x'
python-version: "3.x"

- name: Build the packages
# see https://github.com/docker/build-push-action/issues/252
Expand Down Expand Up @@ -107,12 +107,15 @@ jobs:
path: debs/*

build-wheels:
name: Build wheels on ${{ matrix.os }} for ${{ matrix.arch }}
name: Build wheels on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
strategy:
matrix:
os: [ubuntu-24.04, macos-13]
arch: [x86_64, aarch64]
os:
- ubuntu-24.04
- ubuntu-24.04-arm
- macos-13 # This uses x86-64
- macos-14 # This uses arm64
# is_pr is a flag used to exclude certain jobs from the matrix on PRs.
# It is not read by the rest of the workflow.
is_pr:
Expand All @@ -122,12 +125,11 @@ jobs:
# Don't build macos wheels on PR CI.
- is_pr: true
os: "macos-13"
# Don't build aarch64 wheels on mac.
- os: "macos-13"
arch: aarch64
- is_pr: true
os: "macos-14"
# Don't build aarch64 wheels on PR CI.
- is_pr: true
arch: aarch64
os: "ubuntu-24.04-arm"

steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
Expand All @@ -141,33 +143,20 @@ jobs:
- name: Install cibuildwheel
run: python -m pip install cibuildwheel==3.0.0

- name: Set up QEMU to emulate aarch64
if: matrix.arch == 'aarch64'
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
with:
platforms: arm64

- name: Build aarch64 wheels
if: matrix.arch == 'aarch64'
run: echo 'CIBW_ARCHS_LINUX=aarch64' >> $GITHUB_ENV

- name: Only build a single wheel on PR
if: startsWith(github.ref, 'refs/pull/')
run: echo "CIBW_BUILD="cp39-manylinux_${{ matrix.arch }}"" >> $GITHUB_ENV
run: echo "CIBW_BUILD="cp39-manylinux_*"" >> $GITHUB_ENV

- name: Build wheels
run: python -m cibuildwheel --output-dir wheelhouse
env:
# Skip testing for platforms which various libraries don't have wheels
# for, and so need extra build deps.
CIBW_TEST_SKIP: pp3*-* *i686* *musl*
# Fix Rust OOM errors on emulated aarch64: https://github.com/rust-lang/cargo/issues/10583
CARGO_NET_GIT_FETCH_WITH_CLI: true
CIBW_ENVIRONMENT_PASS_LINUX: CARGO_NET_GIT_FETCH_WITH_CLI

- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: Wheel-${{ matrix.os }}-${{ matrix.arch }}
name: Wheel-${{ matrix.os }}
path: ./wheelhouse/*.whl

build-sdist:
Expand All @@ -179,7 +168,7 @@ jobs:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: '3.10'
python-version: "3.10"

- run: pip install build

Expand All @@ -191,7 +180,6 @@ jobs:
name: Sdist
path: dist/*.tar.gz


# if it's a tag, create a release and attach the artifacts to it
attach-assets:
name: "Attach assets to release"
Expand Down
Loading
Loading