Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.mobile.android > #155984 > unrolled thread
| Started by | MCSM <despammed@mcsm.anonaddy.me> |
|---|---|
| First post | 2026-09-17 21:00 +0200 |
| Last post | 2026-09-19 20:05 +0300 |
| Articles | 4 — 3 participants |
Back to article view | Back to comp.mobile.android
[NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here MCSM <despammed@mcsm.anonaddy.me> - 2026-09-17 21:00 +0200
Re: [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here ReK2 Hispagatos <rek2@usenet_reborn.tui> - 2026-09-18 18:32 +0000
Re: [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here MCSM <despammed@mcsm.anonaddy.me> - 2026-09-19 14:40 +0200
Re: [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here Anton Shepelev <anton.txt@gmail.moc> - 2026-09-19 20:05 +0300
| From | MCSM <despammed@mcsm.anonaddy.me> |
|---|---|
| Date | 2026-09-17 21:00 +0200 |
| Subject | [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here |
| Message-ID | <mn.8cec7ea934007822.0@mcsm.org> |
On SourceForge (or just wait for the notification in the app ;)
https://sourceforge.net/projects/nereo/files/1.4/
This time it’s a "MegaUpdate"! ;)
So, bug fixes only — no more new features request, please! ^^
* STARTTLS now follows both halves of RFC 4642 instead of one. If a
server REFUSES STARTTLS before the handshake, NeReO may carry on
unencrypted as the standard allows, and that is unchanged. But if
the server ACCEPTS (382) and the handshake then fails, RFC 4642
requires both sides to close the connection - and until 1.3.7
NeReO carried on in cleartext instead. That fallback was probably
broken anyway, because the TLS ClientHello had already been
written to the socket, but the point is that it should never have
been attempted. Such a connection now fails with an explicit
message rather than quietly continuing unencrypted.
* The database has been updated (schema version 12). Servers,
groups, articles, filters, identities and drafts are migrated in
place and nothing is deleted - and if NeReO ever meets a version
it cannot migrate, it makes a physical copy first and tells you.
The new structures are not used by anything yet: they are there
for the trust-and-certificates work that follows in this same
release. As always before a version that touches the database, a
backup from Maintenance costs nothing.
* A restore could give a server a user name it never had. Servers
with no account were written to the backup correctly, as an empty
value, but read back as the literal word "null": four characters,
which NeReO then dutifully tried to log in with, on servers that
want no login at all. The server answered "381 Enter password",
NeReO sent an empty password, and the server replied with a syntax
error that meant nothing to anyone. It was a single missing check
among seven fields of the same kind, and it had been there since at
least 1.2.8. Restores are now correct, and any server still
carrying that fake user name is repaired the first time you restore
a backup: the message tells you how many.
* NeReO no longer sends an empty password when a server asks for one.
It says plainly that no password is saved for that server, and
suggests clearing the user name if the server does not need an
account. The check sits where the server actually asked for the
password (a 381 response): a server that is happy with the user
name alone answers 281 and keeps working, as RFC 4643 requires.
* Maintenance has a new "Database diagnostics" panel. It counts the
rows of every table and shows the schema version and the space
used, with a Copy button. It exists because a database migration
that OPENS is not the same as a migration that WORKED: it can be
formally correct and still have emptied a table, and the app would
start perfectly - it is the archive that would be missing. Take the
numbers before an update and again after, and if they match,
nothing was lost. It is also the quickest thing to attach to a bug
report. Nothing is computed until you press the button.
* Replying to a crosspost now shows where the message is actually
going. Until now the compose screen showed only the group you were
reading, even when the reply was set to go out on three. Two
related faults went with it: reopening the group selector to CHECK
your choice silently reset it to the default (the worst possible
case, because the act of checking destroyed what was being
checked), and in the panel layout the crosspost button did not
exist at all, so changing the groups meant abandoning the reply
and starting over. All three reported by Dave Royal.
* "All messages" now works on high-retention servers. Asking for the
whole history of a very large group made NeReO request the entire
article range in one go, and the reply could exceed the 64 MB
ceiling that protects the app from running out of memory: an error,
and nothing downloaded at all. The overview is now fetched in
slices, each one saved before the next is asked for. The ceiling
stays where it was (raising it would have moved the wall, not
removed it) and there are two bonuses: a sync interrupted halfway
now resumes instead of starting over, and memory use no longer
depends on how big the group is. Reported by Bingo3331.
* TLS trust is now something you grant, not something you are handed.
The normal path is unchanged. What changes is what happens when it
FAILS: instead of a dead end, NeReO writes down the identity the
server showed and marks it SEEN, NOT TRUSTED, and the connection
still fails. You approve it later, calmly, from Servers -> TLS
identity, never in a dialog on top of a running sync: a security
warning that interrupts you is the one you click without reading.
What is pinned is the SHA-256 of the leaf public key, never an
intermediate. From then on that key is compared on EVERY
connection,
and if it changes NeReO stops and shows you both, with no "accept
the new one" button. The friction is the feature. There is also a
per-server "expired certificate" exception that relaxes the dates
and nothing else, and goes inert by itself the day the server
renews.
* "Certificate expires in N days" warning. The trust manager sees the
certificate on every connection, so the expiry date is free, and
not
using it would have been a waste. It comes from a real case: an
administrator who renews BY HAND, and a Let's Encrypt certificate
that lives 90 days. That situation is not closed, it is cyclical.
* Accented text no longer breaks in articles with no character set
declaration, or with a wrong one. Of seven measured cases, five
lost
the text; the worst was the WRONG declaration, which produced no
error markers at all, just plausible gibberish that NeReO
re-published in impeccable UTF-8. A three-step rule, ten cases
checked on every build. And because NeReO stores the ALREADY
DECODED
text, there is a new "Reload message" action for the article bar:
without it the fix would be invisible on everything already in your
archive.
* Read follows the Message-ID. A crosspost read in one group counts
as
read in the others: it is one message, and it is what MesNews does.
Watched threads and filters already worked this way; read was the
odd one out. On by default.
* Followup-To read and respected. It was the one GNKSA criterion
NeReO
did not meet. If the author asks for follow-ups to continue
elsewhere, the reply goes THERE, and the compose screen SAYS so:
redirecting without saying it would replace a discourtesy with a
surprise. If you open the groups selector and choose yourself, your
choice wins. The "poster" case does not block posting but warns and
offers the author's address.
* Quote intro settable per group (asked for by Henry The Mole). It
REPLACES the one from your identity instead of joining the random
draw: the point is a deliberate choice, typically the language of
the group.
--
.:. MCSM .:.
-> posting from PC with MesNews <-
[toc] | [next] | [standalone]
| From | ReK2 Hispagatos <rek2@usenet_reborn.tui> |
|---|---|
| Date | 2026-09-18 18:32 +0000 |
| Message-ID | <118k03j$1v4jb$3@matrix.hispagatos.org> |
| In reply to | #155984 |
Very nice!! I am telling people about it, it was much needed
I wrote usenet_reborn for a moderm lite TUI usenet/nntp client
but have no idea of android things so I am telling everyone
about Nere0
any chance you add it to f-droid ?
Happy Hacking
ReK2
> [in reply to MCSM <<mn.8cec7ea934007822.0@mcsm.org>>]
> On SourceForge (or just wait for the notification in the app ;)
> https://sourceforge.net/projects/nereo/files/1.4/
>
> This time it’s a "MegaUpdate"! ;)
>
> So, bug fixes only — no more new features request, please! ^^
>
> * STARTTLS now follows both halves of RFC 4642 instead of one. If a
> server REFUSES STARTTLS before the handshake, NeReO may carry on
> unencrypted as the standard allows, and that is unchanged. But if
> the server ACCEPTS (382) and the handshake then fails, RFC 4642
> requires both sides to close the connection - and until 1.3.7
> NeReO carried on in cleartext instead. That fallback was probably
> broken anyway, because the TLS ClientHello had already been
> written to the socket, but the point is that it should never have
> been attempted. Such a connection now fails with an explicit
> message rather than quietly continuing unencrypted.
> * The database has been updated (schema version 12). Servers,
> groups, articles, filters, identities and drafts are migrated in
> place and nothing is deleted - and if NeReO ever meets a version
> it cannot migrate, it makes a physical copy first and tells you.
> The new structures are not used by anything yet: they are there
> for the trust-and-certificates work that follows in this same
> release. As always before a version that touches the database, a
> backup from Maintenance costs nothing.
> * A restore could give a server a user name it never had. Servers
> with no account were written to the backup correctly, as an empty
> value, but read back as the literal word "null": four characters,
> which NeReO then dutifully tried to log in with, on servers that
> want no login at all. The server answered "381 Enter password",
> NeReO sent an empty password, and the server replied with a syntax
> error that meant nothing to anyone. It was a single missing check
> among seven fields of the same kind, and it had been there since at
> least 1.2.8. Restores are now correct, and any server still
> carrying that fake user name is repaired the first time you restore
> a backup: the message tells you how many.
> * NeReO no longer sends an empty password when a server asks for one.
> It says plainly that no password is saved for that server, and
> suggests clearing the user name if the server does not need an
> account. The check sits where the server actually asked for the
> password (a 381 response): a server that is happy with the user
> name alone answers 281 and keeps working, as RFC 4643 requires.
> * Maintenance has a new "Database diagnostics" panel. It counts the
> rows of every table and shows the schema version and the space
> used, with a Copy button. It exists because a database migration
> that OPENS is not the same as a migration that WORKED: it can be
> formally correct and still have emptied a table, and the app would
> start perfectly - it is the archive that would be missing. Take the
> numbers before an update and again after, and if they match,
> nothing was lost. It is also the quickest thing to attach to a bug
> report. Nothing is computed until you press the button.
> * Replying to a crosspost now shows where the message is actually
> going. Until now the compose screen showed only the group you were
> reading, even when the reply was set to go out on three. Two
> related faults went with it: reopening the group selector to CHECK
> your choice silently reset it to the default (the worst possible
> case, because the act of checking destroyed what was being
> checked), and in the panel layout the crosspost button did not
> exist at all, so changing the groups meant abandoning the reply
> and starting over. All three reported by Dave Royal.
> * "All messages" now works on high-retention servers. Asking for the
> whole history of a very large group made NeReO request the entire
> article range in one go, and the reply could exceed the 64 MB
> ceiling that protects the app from running out of memory: an error,
> and nothing downloaded at all. The overview is now fetched in
> slices, each one saved before the next is asked for. The ceiling
> stays where it was (raising it would have moved the wall, not
> removed it) and there are two bonuses: a sync interrupted halfway
> now resumes instead of starting over, and memory use no longer
> depends on how big the group is. Reported by Bingo3331.
> * TLS trust is now something you grant, not something you are handed.
> The normal path is unchanged. What changes is what happens when it
> FAILS: instead of a dead end, NeReO writes down the identity the
> server showed and marks it SEEN, NOT TRUSTED, and the connection
> still fails. You approve it later, calmly, from Servers -> TLS
> identity, never in a dialog on top of a running sync: a security
> warning that interrupts you is the one you click without reading.
> What is pinned is the SHA-256 of the leaf public key, never an
> intermediate. From then on that key is compared on EVERY
> connection,
> and if it changes NeReO stops and shows you both, with no "accept
> the new one" button. The friction is the feature. There is also a
> per-server "expired certificate" exception that relaxes the dates
> and nothing else, and goes inert by itself the day the server
> renews.
> * "Certificate expires in N days" warning. The trust manager sees the
> certificate on every connection, so the expiry date is free, and
> not
> using it would have been a waste. It comes from a real case: an
> administrator who renews BY HAND, and a Let's Encrypt certificate
> that lives 90 days. That situation is not closed, it is cyclical.
> * Accented text no longer breaks in articles with no character set
> declaration, or with a wrong one. Of seven measured cases, five
> lost
> the text; the worst was the WRONG declaration, which produced no
> error markers at all, just plausible gibberish that NeReO
> re-published in impeccable UTF-8. A three-step rule, ten cases
> checked on every build. And because NeReO stores the ALREADY
> DECODED
> text, there is a new "Reload message" action for the article bar:
> without it the fix would be invisible on everything already in your
> archive.
> * Read follows the Message-ID. A crosspost read in one group counts
> as
> read in the others: it is one message, and it is what MesNews does.
> Watched threads and filters already worked this way; read was the
> odd one out. On by default.
> * Followup-To read and respected. It was the one GNKSA criterion
> NeReO
> did not meet. If the author asks for follow-ups to continue
> elsewhere, the reply goes THERE, and the compose screen SAYS so:
> redirecting without saying it would replace a discourtesy with a
> surprise. If you open the groups selector and choose yourself, your
> choice wins. The "poster" case does not block posting but warns and
> offers the author's address.
> * Quote intro settable per group (asked for by Henry The Mole). It
> REPLACES the one from your identity instead of joining the random
> draw: the point is a deliberate choice, typically the language of
> the group.
>
> --
> .:. MCSM .:.
> -> posting from PC with MesNews <-
--
{gemini,https}://{,rek2.}hispagatos.org - mastodon: @rek2@hispagatos.space
[https|gemini]://2600.Madrid - https://hispagatos.space/@rek2
Reticulum Laptop: lxmf@c6dc6bb3a6b0955d102fde5e7613e2af
Reticulum PC: lxmf@46f7530c35cd9cb2e8e6cf6d39064810
[toc] | [prev] | [next] | [standalone]
| From | MCSM <despammed@mcsm.anonaddy.me> |
|---|---|
| Date | 2026-09-19 14:40 +0200 |
| Message-ID | <mn.9b707ea9171bd2b0.0@mcsm.org> |
| In reply to | #156016 |
On 18/09/2026 , *ReK2 Hispagatos* wrote:
.....
> any chance you add it to f-droid ?
Nope! Not by my side.
Maybe some other people can do this.
I.E. Henry The Mole, another Italian usenet fan, is working on a
possible fork. He is also a fan of F-Droid and Open Source apps for
Android
Have a look here: https://www.themolezone.com/en
PS: Please, in the future, try to avoid replying above the text of a
message. (Top posting)
If you think about it, it breaks the natural flow of reading.
For any given topic, it is better to continue writing below
the quoted text, following the natural reading order. ;)
Otherwise:
the quoted text, following the natural reading order. ;)
For any given topic, it is better to continue writing below
If you think about it, it breaks the natural flow of reading.
--
.:. MCSM .:.
-> posting from PC with MesNews <-
[toc] | [prev] | [next] | [standalone]
| From | Anton Shepelev <anton.txt@gmail.moc> |
|---|---|
| Date | 2026-09-19 20:05 +0300 |
| Message-ID | <20260919200510.3d146eacb46c6328f13d6ea9@gmail.moc> |
| In reply to | #156033 |
MCSM: > Please, in the future, try to avoid replying above the > text of a message. (Top posting) Because it messes up the flow of reading. > How come? > > I prefer to reply inline. > > > What do you do instead? > > > > No. > > > > > Do you like top-posting? -- <https://academickids.com/encyclopedia/index.php/Top-posting> -- () ascii ribbon campaign -- against html e-mail /\ www.asciiribbon.org -- against proprietary attachments
[toc] | [prev] | [standalone]
Back to top | Article view | comp.mobile.android
csiph-web