| 11 Aug 2025 |
emily | it's literally just an admission that state resolution doesn't work right? | 17:43:21 |
K900 | Basically yes | 17:43:31 |
emily | oh I guess you said as much | 17:43:34 |
@emma:rory.gay | i mean, they'vebeen admitting that for ages now | 17:43:48 |
emily | btw it's pretty funny that Synapse failed to put out a working release | 17:43:47 |
emily | after setting their own deadline and then also delaying disclosure 3 weeks | 17:43:55 |
emily | not sure how they managed to avoid running tests or linting during all that sitting around time | 17:44:08 |
@emma:rory.gay | we've always known that state res is a broken mess, we've been joking about state res v3 for years now | 17:44:14 |
@emma:rory.gay | matrix spec is the next valve: cant count to 3 | 17:44:22 |
Charles | also zulip is just massively better for this particular use case (and i would argue better for public rooms in general) (in my testing so far) | 17:47:50 |
Charles | wait what | 17:48:45 |
emily | see https://matrix.to/#/!vxTmkuJzhGPsMdkAOc:transformierende-gesellschaft.org/$Gi9Fk9kEfbkUl4wGImJFL-T5EZO0BJ5ePGTrYRzsD9k?via=utzutzutz.net&via=matrix.org&via=tchncs.de, https://matrix.to/#/!ATURSDtpSAgOTfvtbq:lossy.network/$HJYKt60KYvra3DKIjZq88T18DaMFgaf6Y4fk9eJ_pVM?via=nixos.org&via=matrix.org&via=stratum0.org | 17:49:04 |
Charles | rooms i am not in | 17:49:42 |
Charles | https://github.com/element-hq/synapse/releases but yeah i don't see anything here lol | 17:49:50 |
@emma:rory.gay | yeah they botched teh release | 17:50:04 |
emily | fwiw I was pushing for testing out Zulip during the abuse wave and was offered access to the Zulip that was used during the NCA for playing around with it and pulling in whoever on the mod team might be interested in looking at the tooling etc. | 17:50:03 |
emily | I lost the spark for it when the abuse wave died down | 17:50:13 |
emily | but if you are interested in pushing for a move to Zulip I would guess that offer of access still stands | 17:50:24 |
emily | I was discussing it with uep at the time | 17:50:35 |
emily | it's tagged | 17:50:44 |
emily | but it fails many tests | 17:50:47 |
emily | and broke linting CI | 17:50:51 |
Charles | ah lol | 17:50:59 |
emily | so I guess they just did not test it⦠? | 17:51:00 |
Gnuxie ππ | @matthew is this true meow? | 17:51:52 |
@emma:rory.gay | element matthew isnt here... lol | 17:52:15 |
K900 | Well the vuln seems to be "you can force well-behaved servers to roll back to any previous room state" | 17:52:27 |
emily | (it was sil's offer, I think he asked me to open an issue in NixOS/org or something for it?) | 17:52:28 |
K900 | Which isn't quite "arbitrary state overwrite" | 17:52:40 |
Charles | i ended up setting up my own zulip instance that i've primarily been using fwiw | 17:52:44 |