Released on September 30, 2026.
-
Upgraded Fedify to 2.2.14, which fixes a security vulnerability where the remote document loaders followed unbounded chains of alternate document links, which could exhaust resources during remote key and document resolution. Alternate links now share the 20-hop limit and loop detection with HTTP redirects, and preserve the caller's cancellation signal. [GHSA-97w4-f4rq-mgqm]
-
Added indexes on the post foreign keys in
list_posts,timeline_posts,remote_reply_scrape_jobs,notifications, andnotification_groupsto avoid full table scans during cascading post deletes. On large installations, run these commands before upgrading to avoid blocking writes during the automatic migration. Run each command separately, outside a transaction:CREATE INDEX CONCURRENTLY IF NOT EXISTS list_posts_post_id_index ON public.list_posts (post_id); CREATE INDEX CONCURRENTLY IF NOT EXISTS timeline_posts_post_id_index ON public.timeline_posts (post_id); CREATE INDEX CONCURRENTLY IF NOT EXISTS remote_reply_scrape_jobs_post_id_index ON public.remote_reply_scrape_jobs (post_id); CREATE INDEX CONCURRENTLY IF NOT EXISTS notifications_target_post_id_index ON public.notifications (target_post_id); CREATE INDEX CONCURRENTLY IF NOT EXISTS notification_groups_target_post_id_index ON public.notification_groups (target_post_id);
The migration reuses existing indexes with these names after checking their definitions and validity. This includes indexes created for the workaround in #624. If a concurrent build fails or is interrupted, PostgreSQL can leave an invalid index behind. Drop only the affected index with
DROP INDEX CONCURRENTLY public.<index_name>and retry its creation command before upgrading. An existing index with an unexpected definition also causes the migration to fail; inspect it before replacing it. [#624, #626]