chore: upgrade MAS to 1.25.1 #7

Open
autonomic-bot wants to merge 2 commits from upgrade-358b376 into main
Owner

Recipe upgrade — matrix-synapse (extends PR #7)

This extends the existing upgrade PR (branch upgrade-358b376) with today's delta: MAS 1.24.0 → 1.25.1 (last week's pass had it at 1.25.0). One evolving upgrade PR; no second PR.

Image tag table

service image current (upstream main) new (this PR)
app matrixdotorg/synapse v1.161.0 v1.161.0 (unchanged — latest stable; v1.162.0rc1 is a pre-release)
mas ghcr.io/element-hq/matrix-authentication-service 1.24.0 1.25.1
signalbridge dock.mau.dev/mautrix/signal v0.2609.0 v0.2609.0 (held — "v26.02.2" is a downgrade, see below)
telegrambridge dock.mau.dev/mautrix/telegram v0.2609.0 v0.2609.0 (current)
discordbridge halfshot/matrix-appservice-discord v1.0.0 v1.0.0 (current)
web nginx 1.31.6 1.31.6 (current)
admin awesometechnologies/synapse-admin 0.11.4 0.11.4 (current)
db pgautoupgrade/pgautoupgrade 18-alpine 18-alpine (current)
signaldb / telegramdb / discorddb postgres 13-alpine 13-alpine (held deliberately)

Diff: 1 line — compose.mas.yml MAS image 1.24.0 → 1.25.1.

Upstream release notes

  • mas 1.24.0 → 1.25.1: https://github.com/element-hq/matrix-authentication-service/releases
    • v1.25.0 (2026-09-21): bug fixes only — back_to_client template error when no state param (#5922); policy-violation rendering with empty code (#5921); translations; internal/CI; http-body-util 0.1.3→0.1.5. Notable behavioral change: M_APPSERVICE_LOGIN_UNSUPPORTED returned for m.login.application_service (#5961).
    • v1.25.1 (2026-09-21): one bugfix — rendering of the password registration page when a CAPTCHA provider is configured (#5992).
    • No breaking changes, no config-schema changes, no new required config. DB migrations run automatically on startup (verified live below).
  • mautrix/signal v0.2609.0 → "v26.02.2": DECLINED. v26.09 (git/docker tag v0.2609.0, released 16 Sep 2026) is the GitHub [Latest] release. v26.02.2 is the display-name form of v0.2602.2, released 02 Mar 2026 — ~7 months older. abra's semver-ish sort mis-reports it as an upgrade. The recipe correctly pins dock.mau.dev/mautrix/signal:v0.2609.0. https://github.com/mautrix/signal/releases

Held: bridge DBs at postgres:13-alpine

The 14/15/16/17/18-alpine "upgrades" abra reports are MAJOR pg jumps; plain postgres cannot auto-migrate a data dir across majors, so an unattended bump would crash-loop deployments with existing bridge data. Established recipe precedent — not bumped here.

Operator Action Required

None. MAS is an optional overlay (compose.mas.yml); deployments without MAS are unaffected. MAS 1.25.x is a drop-in bugfix line (1.25.0 + 1.25.1). No config/secrets/DB changes; migrations auto-run on startup.

Security

Advisory scan (deterministic, --from 1.161.0 --to 1.161.0 --image matrix-authentication-service=1.24.0:1.25.1 --image mautrix/signal=v0.2609.0:v26.02.2): 0 CVEs fixed identified; 24 sources checked, no failed sources. Union with release-note reading: 0 CVEs fixed by this window (MAS 1.25.0/1.25.1 name no security fixes).

Recommended release command (operator, after merge)

The version label (7.3.2+v1.161.0) is intentionally untouched in this PR.

abra recipe release matrix-synapse -z

→ publishes 7.3.3+v1.161.0 (bugfix-only sidecar bump; app image unchanged).

Live verification (step 2b, cc-ci direct deploy)

dev-matrix-synapse.ci.commoninternet.net deployed --chaos with the MAS overlay + secrets enabled:

  • all 4 services (app, db, mas, web) converged 1/1
  • mas logs: Starting up version="v1.25.1" → Running pending database migrations → Syncing providers and clients → Listening on http://[::]:8080; worker leader elected
  • running image digest sha256:54f03be8ef26b9a6f2ab594d2a4c6e8074c3c09fbe05890a00ea50939d3e152a — matches the upstream v1.25.1 release artifact exactly
  • synapse serves /_matrix/client/versions (HTTP 200, full manifest) via nginx 1.31.6; web / → 302
  • teardown verified: 0 stacks / 0 volumes / 0 secrets with the dev-matrix-synapse prefix

Tested on the cc-ci recipe CI server (!testme, full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

## Recipe upgrade — matrix-synapse (extends PR #7) This extends the existing upgrade PR (branch `upgrade-358b376`) with today's delta: **MAS 1.24.0 → 1.25.1** (last week's pass had it at 1.25.0). One evolving upgrade PR; no second PR. ### Image tag table | service | image | current (upstream main) | new (this PR) | |---|---|---|---| | app | matrixdotorg/synapse | v1.161.0 | v1.161.0 (unchanged — latest stable; v1.162.0rc1 is a pre-release) | | mas | ghcr.io/element-hq/matrix-authentication-service | 1.24.0 | **1.25.1** | | signalbridge | dock.mau.dev/mautrix/signal | v0.2609.0 | v0.2609.0 (**held** — "v26.02.2" is a downgrade, see below) | | telegrambridge | dock.mau.dev/mautrix/telegram | v0.2609.0 | v0.2609.0 (current) | | discordbridge | halfshot/matrix-appservice-discord | v1.0.0 | v1.0.0 (current) | | web | nginx | 1.31.6 | 1.31.6 (current) | | admin | awesometechnologies/synapse-admin | 0.11.4 | 0.11.4 (current) | | db | pgautoupgrade/pgautoupgrade | 18-alpine | 18-alpine (current) | | signaldb / telegramdb / discorddb | postgres | 13-alpine | 13-alpine (**held deliberately**) | Diff: 1 line — `compose.mas.yml` MAS image `1.24.0` → `1.25.1`. ### Upstream release notes - **mas 1.24.0 → 1.25.1**: https://github.com/element-hq/matrix-authentication-service/releases - v1.25.0 (2026-09-21): bug fixes only — `back_to_client` template error when no `state` param (#5922); policy-violation rendering with empty `code` (#5921); translations; internal/CI; `http-body-util` 0.1.3→0.1.5. Notable behavioral change: `M_APPSERVICE_LOGIN_UNSUPPORTED` returned for `m.login.application_service` (#5961). - v1.25.1 (2026-09-21): one bugfix — rendering of the password registration page when a CAPTCHA provider is configured (#5992). - **No breaking changes, no config-schema changes, no new required config.** DB migrations run automatically on startup (verified live below). - **mautrix/signal v0.2609.0 → "v26.02.2"**: DECLINED. `v26.09` (git/docker tag `v0.2609.0`, released 16 Sep 2026) is the GitHub `[Latest]` release. `v26.02.2` is the display-name form of `v0.2602.2`, released **02 Mar 2026** — ~7 months older. abra's semver-ish sort mis-reports it as an upgrade. The recipe correctly pins `dock.mau.dev/mautrix/signal:v0.2609.0`. https://github.com/mautrix/signal/releases ### Held: bridge DBs at postgres:13-alpine The 14/15/16/17/18-alpine "upgrades" abra reports are MAJOR pg jumps; plain postgres cannot auto-migrate a data dir across majors, so an unattended bump would crash-loop deployments with existing bridge data. Established recipe precedent — not bumped here. ### Operator Action Required None. MAS is an optional overlay (`compose.mas.yml`); deployments without MAS are unaffected. MAS 1.25.x is a drop-in bugfix line (1.25.0 + 1.25.1). No config/secrets/DB changes; migrations auto-run on startup. ### Security Advisory scan (deterministic, `--from 1.161.0 --to 1.161.0 --image matrix-authentication-service=1.24.0:1.25.1 --image mautrix/signal=v0.2609.0:v26.02.2`): **0 CVEs fixed identified**; 24 sources checked, no failed sources. Union with release-note reading: **0 CVEs fixed by this window** (MAS 1.25.0/1.25.1 name no security fixes). ### Recommended release command (operator, after merge) The version label (`7.3.2+v1.161.0`) is intentionally untouched in this PR. ``` abra recipe release matrix-synapse -z ``` → publishes `7.3.3+v1.161.0` (bugfix-only sidecar bump; app image unchanged). ### Live verification (step 2b, cc-ci direct deploy) `dev-matrix-synapse.ci.commoninternet.net` deployed `--chaos` with the MAS overlay + secrets enabled: - all 4 services (`app`, `db`, `mas`, `web`) converged **1/1** - mas logs: `Starting up version="v1.25.1"` → `Running pending database migrations` → `Syncing providers and clients` → `Listening on http://[::]:8080`; worker leader elected - running image digest `sha256:54f03be8ef26b9a6f2ab594d2a4c6e8074c3c09fbe05890a00ea50939d3e152a` — **matches the upstream v1.25.1 release artifact exactly** - synapse serves `/_matrix/client/versions` (HTTP 200, full manifest) via nginx 1.31.6; web `/` → 302 - teardown verified: 0 stacks / 0 volumes / 0 secrets with the `dev-matrix-synapse` prefix Tested on the cc-ci recipe CI server (`!testme`, full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-09-21 18:38:50 +00:00
chore: upgrade MAS to 1.25.0
cc-ci/testme cc-ci: success
358b3769c7
autonomic-bot requested review from trav 2026-09-21 18:38:50 +00:00
autonomic-bot requested review from notplants 2026-09-21 18:38:50 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — matrix-synapse @ 358b3769 ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `matrix-synapse` @ `358b3769` ✅ **passed** [![cc-ci result card](https://ci.autonomic.zone/runs/4/summary.png)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/4) [![level](https://ci.autonomic.zone/runs/4/badge.svg)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/4) [full logs](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/4) · [dashboard](https://ci.autonomic.zone/)
autonomic-bot changed title from chore: upgrade MAS to 1.25.0 to chore: upgrade MAS to 1.25.1 2026-09-28 21:49:01 +00:00
autonomic-bot added 1 commit 2026-09-28 21:49:02 +00:00
chore: upgrade MAS to 1.25.1
cc-ci/testme cc-ci: success
9960b74fd6
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — matrix-synapse @ 9960b74f ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `matrix-synapse` @ `9960b74f` ✅ **passed** [![cc-ci result card](https://ci.autonomic.zone/runs/22/summary.png)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/22) [![level](https://ci.autonomic.zone/runs/22/badge.svg)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/22) [full logs](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/22) · [dashboard](https://ci.autonomic.zone/)
All checks were successful
cc-ci/testme cc-ci: success
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin upgrade-358b376:upgrade-358b376
git checkout upgrade-358b376
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/matrix-synapse#7