CI Report:
N/A
LinuxServer Changes:
Full Changelog: v4.6.3-ls202...v4.6.4-ls203
Remote Changes:
Upgrade overview
This release contains upgrade notes that deviate from the norm:
ℹ️ Requires assets recompilation
For more information, view the complete release notes and scroll down to the upgrade instructions section.
Changelog
Security
- Fix incorrect permission enforcement (GHSA-7jvv-fhmg-wpfw, GHSA-hx34-2pfw-2qfj)
- Fix SSRF protection bypass via IPv4-compatible IPv6 addresses (GHSA-vwhj-3g83-v276)
- Update dependencies
Changed
Fixed
- Fix being unable to vote in polls without an expiration date (#39949 by @ClearlyClaire)
- Fix performance of user-focused queries in admin dashboard (#39929 by @ClearlyClaire)
- Fix Web Push subscription deletion endpoint incorrectly expecting anti-CSRF tokens (#39918 by @ClearlyClaire)
- Fix
ActivityPub::Activity::Createtrying to re-create known statuses when author changes (#39916 by @ClearlyClaire) - Fix typo in quotes list error handling (#39904 by @shleeable)
- Fix lax relevancy check in inbound activity processing (#39892 by @ClearlyClaire)
- Fix
Account::Mergingconcern not supporting Quotes or Collections, refactor it (#39884 by @ClearlyClaire) - Fix various emoji search issues (#39815 by @ChaosExAnima)
- Fix swapped order of "accept/reject" actions in follow requests (#39862 by @diondiondion)
- Fix suspended accounts not being removed from follow request count in
/api/v1/accounts/verify_credentials(#39858 by @ClearlyClaire) - Fix "Learn more" link target in column post privacy hint (#39829 by @diondiondion)
- Fix page refresh when trying to save custom profile fields (#39828 by @diondiondion)
- Fix followed tags not being properly cleaned up when an account is deleted (#39824 by @shleeable)
- Fix CW being copied to body when editing quote posts with empty text (#39823 and #39837 by @shleeable and @ClearlyClaire)
- Fix handling of
QuoteRequestrejections when those can't be found byid(#39820 by @shleeable) - Fix autofollow option being ignored in invite moderation interface (#39819 by @shleeable)
- Fix pagination overlapping announcement reactions bar (#39814 by @diondiondion)
- Fix very wide images overflowing posts horizontally (#39812 by @diondiondion)
- Fix collections not being removed when an account is deleted (#39809 by @oneiros)
- Fix account followed languages selector (#39801 by @ChaosExAnima)
- Fix error handling in
ActivityPub::ProcessFeaturedItemService(#39787 by @ClearlyClaire) - Fix display of past relative times (#39742 by @ClearlyClaire)
- Fix pinned post button width (#39724 by @ChaosExAnima)
Upgrade notes
To get the code for v4.6.4, use git fetch && git checkout v4.6.4.
Note
As always, make sure you have backups of the database before performing any upgrades. If you are using docker-compose, this is how a backup command might look: docker exec mastodon_db_1 pg_dump -Fc -U postgres postgres > name_of_the_backup.dump
Dependencies
External dependencies have not changed since v4.6.0.
- Ruby: 3.3 or newer
- PostgreSQL: 14 or newer
- Elasticsearch (recommended, for full-text search): 7.x (OpenSearch should also work)
- LibreTranslate (optional, for translations): 1.3.3 or newer
- Redis: 7.0 or newer
- Node: 22 or newer
- libvips: 8.13 or newer
- FFMpeg: 5.1 or newer
Update steps
The following instructions are for updating from 4.6.3.
If you are upgrading directly from an earlier release, please carefully read the upgrade notes for the skipped releases as well, as they often require extra steps such as database migrations. In particular, it is very important to read the 4.6.0 release notes.
Non-Docker
Tip
The charlock_holmes gem may fail to build on some systems with recent versions of gcc.
If you run into this issue, try BUNDLE_BUILD__CHARLOCK_HOLMES="--with-cxxflags=-std=c++17" bundle install.
- Install dependencies with
bundle installandyarn install --immutable - Precompile the assets:
RAILS_ENV=production bundle exec rails assets:precompile - Restart all Mastodon processes.
When using Docker
- Restart all Mastodon processes.