⚠️ We are planning to release important security fixes for #Mastodon on July 6th, between 13:00 and 15:00 UTC. They will be available for the 4.1, 4.0 and 3.5 versions as well as a nightly release, to make the upgrade as small and painless for everyone as possible. Be ready to upgrade!
@Mastodon @Patrick da müssen wir aktualisieren ;)
@Mastodon
Adding a Rate Limit feature? 😂
@mndflayr @Mastodon jokes aside, some rate limiting function might have helped back in November, when lots of people were coming and many servers weren't able to cope with it.

@Mastodon

In case I'm running the server from the main branch, did I already get the fix or do I still need to update on July 6th?

@mixaill You'll need to update then
@Mastodon Prepared for more Twitter migration
@Mastodon i got 503 error when i publish my post
but it sent it
@Mastodon Is it available to change this? It will improve comfort of using mastodon
@Nie_6969 @Mastodon part of the problem is here, you can subscribe to this bug for updates: https://github.com/mastodon/mastodon/issues/34
Backfill statuses from remote accounts when first subscribed · Issue #34 · mastodon/mastodon

Your self-hosted, globally interconnected microblogging community - Backfill statuses from remote accounts when first subscribed · Issue #34 · mastodon/mastodon

GitHub

@Aranjedeath @Nie_6969 @Mastodon That may be a different issue. When following a user who hasn’t been seen by the server before you’ll typically only see their posts from that point onward, their profile won’t show the posts from before you followed them (the server discovered them).

Whereas that message refers to a user who has migrated and since posts currently cannot be migrated (natively) and so they direct you to the original profile/server to see those posts.

@BenjaminNelan thank you for differentiating, I did know that when I posted (contained within the phrase "part of the problem"). Once you have the software and operational infrastructure to backfill posts... It is not hard to add additional situations where you do so.

@Aranjedeath I agree that it could be done this way and I would prefer it than the current system.

Though may affect how those backfilled posts could be interacted/distributed. Backfill = cache linking to existing ActivityPub objects. In the case of a migrated account where the remote server no longer exists you effectively have zombie posts.

@Aranjedeath Having said that - I just did an experiment with my self-hosted server where I cached old posts from my old account then edited the database to change the owner to the migrated user's new account and... it works just fine...

No idea if there's side effects of doing this, about to try it on a post that has replies. I definitely thought there was more going on under the hood though.

@Nie_6969 @Mastodon this is more or less "by design" in the way how ActivityPub works. So it will most probably never be fixed...

You can fetch the follower count, you can fetch the people who participated in polls, but you can’t fetch likes & boost statistics as well as posts made in the past on another server?

Excuses! It’s easily possible. Even on a client basis.

@Erik @Nie_6969 @Mastodon it is possible in theory, AFAIK yes, but not with ActivityPub itself and it will a lot of load for servers and it's kind of a trade-off question: do we really need the whole history of a user or should we better safe our resources?

@Erik @Nie_6969 @Mastodon @jr

I use @michael's #FediFetcher to do this. You can run it as a GitHub action, server, or desktop computer. Basically, set it up and forget about it. It chugs along backfilling new follows/followers, replies to posts, and more.

https://github.com/nanos/FediFetcher

GitHub - nanos/FediFetcher: FediFetcher is a tool for Mastodon that automatically fetches missing replies and posts from other fediverse instances, and adds them to your own Mastodon instance.

FediFetcher is a tool for Mastodon that automatically fetches missing replies and posts from other fediverse instances, and adds them to your own Mastodon instance. - nanos/FediFetcher

GitHub

@paul Thanks for the mention! Just to set expecatations: FediFetcher works really well to pull in replies, etc (if I say so myself 🙈), but it can sadly not pull in correct likes / boosts count, as Mastodon doesn't have an API for that 😔

@Erik @Nie_6969 @Mastodon @jr

I will absolutely implement this on #MastodonDE! Wow! Thank you so much.
Uden AI Network

@Mastodon Will it include a fix for blocked and muted accounts showing up in Home and Search?
@Mastodon Please no rate limit! 🙏🏻😅
@Mastodon @Blobfox ^
(glitch will likely update too)
@Mastodon Why a two-hour release window? Drop it at a fixed time!

@apicultor @Mastodon It's crazy how bad this is being handled honestly

1. We have no indication of the severity
2. There is a two hour window where we're supposed to keep refreshing to see if the patch for what all we know is a 10.0 CVE score security issue

@Mastodon
Realize I am really ignorant of this stuff ... as a person on a Windows computer using Mastodon in a browser, do I need to do anything?

Can I also assume my android app will also auto-update like all other apps on my phone?

Did I mention that I'm ignorant on all aspect of this issue?

@TopKnot @Mastodon This is an update that the administrators of the Mastodon instances will need to do. No interaction from users needed.
@TopKnot @Mastodon Nothing needed on your end. This is an update for the Mastodon server software. It will be applied by the server administrators.
@TopKnot I’m pretty sure this update is just for server admins, you’re in the clear!
@TopKnot No, you don't need to do anything! Mastodon is the software that's running on the server which is hosting your instance. So the android app is not affected by this at all (but yes, would auto-update like any other app if there was an update for it). Depending on what this update actually changes and if applying it requires restarting the instance, as a user you may not even notice this update at all.

@TopKnot @Mastodon no, this is an announcement for instance administrators, they are the ones that need to update.

For us regular users this means that probably some hours after this our instance might have a bit of downtime while it is being updated, which will depend on your local administrator's time availability (keep in mind that most admins are volunteers with their own jobs and such, so the time can be away from office hours)

@TopKnot @Mastodon Don't worry, this announcement is pretty much just for admins. It's just for server software I think. End users don't need to worry, perhaps unless their server doesn't update.
@TopKnot @Mastodon You don’t need to do anything, this is only relevant for instance admins and developers

@TopKnot

This announcements is for Mastodon instance (server) admins only. Others can ignore it.

@Mastodon

@Mastodon Might be worth editing this post to say it's a server update, and users need not do anything/panic!
@Mastodon with this new release , will support Debian Bookworm?
Meaning: nodejs 18 and libidn12 icu72?
Is Ruby 3.2.2 also full supported ?
@Mastodon waiting for quote post & direct message feature

@arunshah240 @Mastodon direct message does exist as a privacy option for each message, alongside public, unlisted and followers-only.

Quote-posting isn't in plans for Mastodon, but exists in other compatible options, like Calckey, which some instances use.

You can already direct message people on Mastodon!

But I agree, it needs an WebRTC-esque chat that’s compatible with Pleroma, Akkoma, and all the other Fedi platforms that have already implemented it.

@Mastodon @darius do you expect to have a hometown release with this swiftly, or should i expect to have to pull in changes manually?
@alive @Mastodon yes, I have been alerted to this although "swift" will mean "within 24 hours, hopefully 12" because I will be in the middle of airplane travel that day