#mementomorisocial
36 posts · Last used 12d
We are live on @upcloud@glitchy.upcloud.world servers! ![]()
Tonight, we moved mementomori.social from Hetzner to UpCloud servers in Helsinki. We had scheduled a maintenance window from 17:00 to 20:00, but our instance was down for just under an hour - the last post on the old server went out at 18:30, and the first on the new server went out at 19:30.
Some numbers from the move:
- PostgreSQL upgraded from 14 to 18; database size is 210 GB with about 118.5 million posts, 1.27 million known accounts, and 21.7 million media attachments
- 440041 posts written by our own 990 users
- Search: 34.9 million public posts, 1.24 million accounts, and 4.28 million hashtags indexed
- Data checksums enabled, so silent disk corruption now shows up as an error instead of bad data
- Rebuilt 72 text indexes for the new operating system's collation rules, ensuring ä and ö sort correctly. This also freed up about 20 GB
- Now accessible over IPv6 as well!
Every server is now provisioned with Ansible, and the playbooks are public: https://github.com/mementomori-social/ansibles
If your home timeline looks empty, it will repopulate as you use it. Please let us know if anything seems off.
Huge thanks to @rolle@mementomori.social and especially @ikkeT@mementomori.social for putting in countless hours. Thank you @upcloud@glitchy.upcloud.world for sponsoring our non-profit
Media files remain hosted on Cloudflare R2 as before.
We should now be faster, better, more sustainable, and more sovereign than ever. Party on!
We've upgraded our Mastodon server to v4.8.0-alpha.3+mementomods-2026-09-15. That is 98 new commits from upstream since our 6.9.2026 build.
Mastodon 4.7.2 is a security release and it is folded into this build.
🔒 Security
- HEIF and AVIF image decoding has been turned off. These are the formats iPhones use for photos. Mastodon calls this a temporary measure, so it will likely come back once the underlying issue is resolved upstream. No advisory has been published for it yet.
What this means in practice: if you upload a photo straight from an iPhone as HEIC, or an AVIF image, it will now fail instead of being converted. Most phone apps and browsers already hand over JPEG, so many of you will never notice. If an image upload does fail, save or export it as JPEG or PNG and it will go through. Images already uploaded here are unaffected, they were converted at upload time and are stored as JPEG.
🔧 Fixes & improvements
- Replies appear in the right order again (https://github.com/mastodon/mastodon/pull/40481)
- You get the confirmation prompt again when you navigate away with an unsent post (https://github.com/mastodon/mastodon/pull/40478)
- Oversized images are caught before the upload starts instead of failing at the end of it (https://github.com/mastodon/mastodon/pull/30475)
- Submitting the same post twice no longer produces a 500 error (https://github.com/mastodon/mastodon/pull/40439)
- The picture in picture video player no longer slides underneath the side panel (https://github.com/mastodon/mastodon/pull/40484)
- Importing a JSON file that is not a custom filter export now gives a proper error instead of a 500 (https://github.com/mastodon/mastodon/pull/40449)
- Privacy policy links in subscription emails point to the right place (https://github.com/mastodon/mastodon/pull/40486)
- Email footer spacing around our custom footer text is fixed (https://github.com/mastodon/mastodon/pull/40440)
- Counts in the interface are pluralised properly in more places (https://github.com/mastodon/mastodon/pull/40464)
- The standalone Pinned Posts page and its keyboard shortcut have been removed upstream (https://github.com/mastodon/mastodon/pull/40494) Pinned posts still show on profiles exactly as before, only the separate page is gone.
🛡️ Moderation
- Canonical email blocks no longer interfere with freezing or approving accounts (https://github.com/mastodon/mastodon/pull/40463)
- The admin account page now shows whether an account is blocked from trends and follow recommendations (https://github.com/mastodon/mastodon/pull/40398)
- Deleting notification requests in bulk now cleans up the notifications along with them (https://github.com/mastodon/mastodon/pull/40393)
🚀 Under the hood
- The 5.0 redesign took 37 of the 98 commits: the new navigation in the advanced multi-column layout, link cards, quotes, hashtags, the translation button, the post actions menu, and menus shown as sheets on mobile. All of it stays behind a flag, so nothing changes for you yet.
- Deleting an account now also deletes any annual reports generated for it (https://github.com/mastodon/mastodon/pull/40394)
- Reattaching an account with the command line tools clears the pending deletion timestamp (https://github.com/mastodon/mastodon/pull/40430)
📦 Dependency updates
- Routine bumps and translation updates.
🏠 Changes specific to our server
- Signing up through an app now requires an invite. The sign up form on the website is behind Turnstile, but the API path that mobile apps use was not, and a wave of bots had been coming through it for days, filling our moderation queue with fake applications. Requiring an invite closes that path. The normal sign up form on the website is untouched and works exactly as before, so if you are pointing someone here, send them to the website.
- Our periodic search index rebuild had been failing with an error since the 6.9.2026 build and now runs again. Live search was never affected by this, only the scheduled full rebuild.
Source code: https://github.com/mementomori-social/mastodon
As always, if you notice anything unusual or buggy, please reach out to me or any of the admins. Enjoy your time here, and feel free to message me with any questions or thoughts. ![]()
If anything feels off, please let us know!
We've upgraded our Mastodon server to v4.8.0-alpha.3+mementomods-2026-09-15. That is 98 new commits from upstream since our 6.9.2026 build.
Mastodon 4.7.2 is a security release and it is folded into this build.
🔒 Security
- HEIF and AVIF image decoding has been turned off. These are the formats iPhones use for photos. Mastodon calls this a temporary measure, so it will likely come back once the underlying issue is resolved upstream. No advisory has been published for it yet.
What this means in practice: if you upload a photo straight from an iPhone as HEIC, or an AVIF image, it will now fail instead of being converted. Most phone apps and browsers already hand over JPEG, so many of you will never notice. If an image upload does fail, save or export it as JPEG or PNG and it will go through. Images already uploaded here are unaffected, they were converted at upload time and are stored as JPEG.
🔧 Fixes & improvements
- Replies appear in the right order again (https://github.com/mastodon/mastodon/pull/40481)
- You get the confirmation prompt again when you navigate away with an unsent post (https://github.com/mastodon/mastodon/pull/40478)
- Oversized images are caught before the upload starts instead of failing at the end of it (https://github.com/mastodon/mastodon/pull/30475)
- Submitting the same post twice no longer produces a 500 error (https://github.com/mastodon/mastodon/pull/40439)
- The picture in picture video player no longer slides underneath the side panel (https://github.com/mastodon/mastodon/pull/40484)
- Importing a JSON file that is not a custom filter export now gives a proper error instead of a 500 (https://github.com/mastodon/mastodon/pull/40449)
- Privacy policy links in subscription emails point to the right place (https://github.com/mastodon/mastodon/pull/40486)
- Email footer spacing around our custom footer text is fixed (https://github.com/mastodon/mastodon/pull/40440)
- Counts in the interface are pluralised properly in more places (https://github.com/mastodon/mastodon/pull/40464)
- The standalone Pinned Posts page and its keyboard shortcut have been removed upstream (https://github.com/mastodon/mastodon/pull/40494) Pinned posts still show on profiles exactly as before, only the separate page is gone.
🛡️ Moderation
- Canonical email blocks no longer interfere with freezing or approving accounts (https://github.com/mastodon/mastodon/pull/40463)
- The admin account page now shows whether an account is blocked from trends and follow recommendations (https://github.com/mastodon/mastodon/pull/40398)
- Deleting notification requests in bulk now cleans up the notifications along with them (https://github.com/mastodon/mastodon/pull/40393)
🚀 Under the hood
- The 5.0 redesign took 37 of the 98 commits: the new navigation in the advanced multi-column layout, link cards, quotes, hashtags, the translation button, the post actions menu, and menus shown as sheets on mobile. All of it stays behind a flag, so nothing changes for you yet.
- Deleting an account now also deletes any annual reports generated for it (https://github.com/mastodon/mastodon/pull/40394)
- Reattaching an account with the command line tools clears the pending deletion timestamp (https://github.com/mastodon/mastodon/pull/40430)
📦 Dependency updates
- Routine bumps and translation updates.
🏠 Changes specific to our server
- Signing up through an app now requires an invite. The sign up form on the website is behind Turnstile, but the API path that mobile apps use was not, and a wave of bots had been coming through it for days, filling our moderation queue with fake applications. Requiring an invite closes that path. The normal sign up form on the website is untouched and works exactly as before, so if you are pointing someone here, send them to the website.
- Our periodic search index rebuild had been failing with an error since the 6.9.2026 build and now runs again. Live search was never affected by this, only the scheduled full rebuild.
Source code: https://github.com/mementomori-social/mastodon
As always, if you notice anything unusual or buggy, please reach out to me or any of the admins. Enjoy your time here, and feel free to message me with any questions or thoughts. ![]()
If anything feels off, please let us know!
We've upgraded our Mastodon server to v4.7.0-alpha.2+mementomods-2026-07-27. A small one this time, mostly a security update, with 6 new commits from upstream since yesterday's build (mementomods-2026-07-26).
Upstream released 4.6.4 with three advisories, and those fixes are now in the nightly line we run:
Security:
- Two permission enforcement fixes, where some admin statistics and retention endpoints could be reached without the right role https://github.com/mastodon/mastodon/security/advisories/GHSA-7jvv-fhmg-wpfw and https://github.com/mastodon/mastodon/security/advisories/GHSA-hx34-2pfw-2qfj
- An SSRF protection bypass through IPv4 compatible IPv6 addresses, which could be used to make the server fetch addresses it should refuse https://github.com/mastodon/mastodon/security/advisories/GHSA-vwhj-3g83-v276
Fixes & improvements:
- Polls without an expiration date can be voted in again https://github.com/mastodon/mastodon/pull/39949
- Tighter enforcement of the collection item limit https://github.com/mastodon/mastodon/pull/39969
As always, if you notice anything unusual or buggy, please reach out to me or any of the admins. Enjoy your time here, and feel free to message me with any questions or thoughts. ![]()
If anything feels off, please let us know!
We have successfully upgraded our Mastodon server to v4.7.0-alpha.1+mementomods-2026-07-26, running Mastodon Bird UI 4.0.0 nightly branch (new alpha for Mastodon v4.7.0-alpha coming soon). This daily build stays on the v4.7.0-alpha.1 nightly line, so this is a within-cycle daily build rather than a version jump, we've just brought it fully up to date with upstream, as our bi-weekly upgrades go.
This update includes 142 new commits from upstream since our 5.7.2026 build (mementomods-2026-07-05). The Docker build is also being updated according to our automatic workflow.
What's new in Mastodon core, these are the changes the Mastodon Team have introduced in the latest nightly version we are running:
✨️ New features
- Groundwork for the Mastodon 5.0 redesign started landing: new design tokens, webfonts and redesigned buttons, toggles and text inputs. It all sits behind a feature flag for now, so nothing changes visually yet https://github.com/mastodon/mastodon/pull/39802
- Emoji search was improved, so shortcodes find better matches https://github.com/mastodon/mastodon/pull/39815
- Remote accounts can now change their handle without breaking follows https://github.com/mastodon/mastodon/pull/39785
- Boosts are deduplicated across the last 80 posts instead of the last 40, so the same post repeats less often in your timeline https://github.com/mastodon/mastodon/pull/39784
- Admins now get notified about out of support Mastodon versions, with end of support dates shown next to available updates https://github.com/mastodon/mastodon/pull/39734
🔧 Fixes & improvements
- "Hide media with a warning" filters are applied correctly again https://github.com/mastodon/mastodon/pull/39946
- Very wide images no longer overflow posts horizontally https://github.com/mastodon/mastodon/pull/39812
- Embedded videos no longer restart when you interact with the post, or with other posts in the same feed https://github.com/mastodon/mastodon/pull/39746
- Quote post text can be edited again https://github.com/mastodon/mastodon/pull/39837 and the content warning is no longer copied into the body when editing a quote with empty text https://github.com/mastodon/mastodon/pull/39823
- The accept and reject actions in follow requests are no longer swapped https://github.com/mastodon/mastodon/pull/39862
- Saving custom profile fields no longer refreshes the page https://github.com/mastodon/mastodon/pull/39828
- The account language selector works again https://github.com/mastodon/mastodon/pull/39801
- Relative timestamps were fixed https://github.com/mastodon/mastodon/pull/39742
- Timelines can load more posts again when the last item is a follow suggestion carousel https://github.com/mastodon/mastodon/pull/39773
- Notification filter selection is kept after changing settings https://github.com/mastodon/mastodon/pull/39872
- Announcement reaction bars no longer overlap pagination https://github.com/mastodon/mastodon/pull/39814
- The admin dashboard and the admin collection page got noticeably faster queries https://github.com/mastodon/mastodon/pull/39929
🔒 Federation & security (under the hood)
- Added support for outgoing HTTP Message Signatures, part of the ongoing work to harden how servers verify each other's requests https://github.com/mastodon/mastodon/pull/39756
- Added ML-DSA-44 support for Object Integrity Proofs and keys, a post quantum signature scheme https://github.com/mastodon/mastodon/pull/39522
- Tightened the relevancy check on incoming activities https://github.com/mastodon/mastodon/pull/39892
- Remote accounts are now deleted when fetching them returns 410 Gone https://github.com/mastodon/mastodon/pull/39865
- Suspended accounts no longer linger in the follow request count https://github.com/mastodon/mastodon/pull/39858
📦 Dependency updates
- Routine bumps this round (Ruby 4.0.6, Bundler 4.0.16, Yarn, Vite, formatjs, AWS SDK, CI actions and translation updates).
🏠 Changes specific to our server
- The "For you" feed is a lot faster and no longer times out when the server is busy. The ranking is now cached and refreshed in the background instead of being calculated from scratch on every single load.
- Emoji autocomplete now puts whole word matches first, so typing :sweat also finds :grinning_face_with_sweat: instead of only custom emojis that happen to contain those letters.
- Lots of performance improvements under the hood.
🐦⬛ Mastodon Bird UI (nightly)
Still on unreleased nighly branch, with a batch of navigation fixes vendored in this round:
- The left navigation scrolls properly at extreme browser zoom on low resolution screens, and only on desktop, so the mobile drawer is left alone.
- The mobile navigation bar sits above the slideout pane again, so it no longer covers the hamburger menu, and the mobile navigation links got proper padding.
- Fixed the compact navigation font size on screens below 1080px height, which was being overridden by the desktop rule.
- Navigation hover highlights are no longer clipped on their left edge on larger screens.
Source code for our Mastodon: https://github.com/mementomori-social/mastodon
As always, if you notice anything unusual or buggy, please reach out to me or any of the admins. Enjoy your time here, and feel free to message me with any questions or thoughts. ![]()
If anything feels off, please let us know!
We just upgraded our Mastodon fork on Mementomori.social to Mastodon 4.6.0 theme variations.
Mastodon Bird UI is now at 4.0.0-alpha.8.rc with support for Color scheme and Contrast settings.
New settings in Settings → Preferences → Appearance:
- Use stars instead of hearts for favourites
- Hide Translate links on Finnish posts
- Hide all Translate links
These used to be separate themes; now you can mix and match.
The Theme dropdown is shorter for the same reason: Light, Dark and Contrast moved into Mastodon's own radios just below the dropdown. If your previous theme is gone, pick Mastodon Bird UI and set Color scheme + tick the new checkboxes to match what you had.
Fixes in Mastodon Bird UI:
- Star icon alignment when Reduce motion is enabled
- Sparkle and ring animations now fire in both motion modes
- Notification colors that disappeared when your OS was light but Mastodon was set to dark
If anything feels off, let me or the admins know. ![]()
Technical details: https://github.com/rollecode/mastodon-bird-ui/releases/tag/4.0.0-alpha.8.rc
#MementoMoriSocial #Mastodon #MastoAdmin #MastodonBirdUI #BirdUI

