- cross-posted to:
- selfhosted@lemmy.world
- cross-posted to:
- selfhosted@lemmy.world
Continuwuity 0.5.6
You’ve got mail! Well, actually, you’ve got a homeserver update to install. And if you don’t have an update to install because you aren’t already using continuwuity, then you’ve still got a homeserver update to install, because you should be using continuwuity anyway.
What’s changed since 0.5.5? idk, I just deliver the mail. You should read the changelog for the v0.5.6 release to see what’s new. I guess I also help write the server, so I can tell you some of the things that changed, but it’s important that you know this wasn’t in the job description when I signed up.
- 🔐 Support for “MSC3814 Dehydrated Devices” has been added, meaning you can now receive encrypted messages without being logged in (supporting client is not included).
- 🕷️ URL previews have had their reliability boosted with new configurable user agents, and a dedicated purge command to remove old ones.
- 🌪️ Massive improvements to performance for inbound federation (from other servers), which has also increased reliability.
- 🕴️ Added partial support for appservice device masquerading, which should decrease issues encountered with mautrix bridges.
There were also some (low severity) security fixes in this release:
- Fixed a data amplification vulnerability (CWE-409) that could be exploited when some compression algorithms were enabled.
- Removed the theoretical ability for escaped admin commands (
\!adminin rooms other than the admin room) to be executed over federation. This is a followup enhancement to further improve the resilliance to attacks similar to CVE-2026-24471 and CVE-2025-68667.
Another important change in this release: federated presence is now disabled by default. Typing indicators and read receipts are still enabled by default, although their documentation has been updated to reflect the cost of using them. Local presence is still enabled by default, so users on the same homeserver can still see each others’ online/unavailable/offline status, but it will no longer federate to other servers unless explicitly enabled. Also, there is a bug in 0.5.5 and below with our policy server implementation - if you do not update to 0.5.6, and join a room with both the stable event type, and the unstable event type, you will encounter “duplicate state” errors when trying to process others’ events. This cannot be resolved without upgrading.
Questions? Concerns? Write me via carrier pigeon. Or join #continuwuity:continuwuity.org, that works too.
Also, we once again have even more rooms. If you look in our space: #space:continuwuity.org, you can explore some of the more topical-but-not-continuwuity rooms, such as our now popular #techtopic:continuwuity.org room, which is basically our offtopic room, but for the more technical discussions not everyone there will care about. As always, everyone is welcome in our general rooms, you don’t have to be running continuwuity or even care about the project to join in!
Anyway. Woof.


