Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > news.software.readers > #37800
| From | ReK2 Hispagatos <rek2@usenet_reborn.tui> |
|---|---|
| Newsgroups | news.software.readers, alt.comp.software.newsreaders, comp.mobile.android |
| Subject | Re: [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here |
| Date | 2026-09-18 18:32 +0000 |
| Organization | Hispagatos.org |
| Message-ID | <118k03j$1v4jb$3@matrix.hispagatos.org> (permalink) |
| References | <mn.8cec7ea934007822.0@mcsm.org> |
Cross-posted to 3 groups.
Very nice!! I am telling people about it, it was much needed
I wrote usenet_reborn for a moderm lite TUI usenet/nntp client
but have no idea of android things so I am telling everyone
about Nere0
any chance you add it to f-droid ?
Happy Hacking
ReK2
> [in reply to MCSM <<mn.8cec7ea934007822.0@mcsm.org>>]
> On SourceForge (or just wait for the notification in the app ;)
> https://sourceforge.net/projects/nereo/files/1.4/
>
> This time it’s a "MegaUpdate"! ;)
>
> So, bug fixes only — no more new features request, please! ^^
>
> * STARTTLS now follows both halves of RFC 4642 instead of one. If a
> server REFUSES STARTTLS before the handshake, NeReO may carry on
> unencrypted as the standard allows, and that is unchanged. But if
> the server ACCEPTS (382) and the handshake then fails, RFC 4642
> requires both sides to close the connection - and until 1.3.7
> NeReO carried on in cleartext instead. That fallback was probably
> broken anyway, because the TLS ClientHello had already been
> written to the socket, but the point is that it should never have
> been attempted. Such a connection now fails with an explicit
> message rather than quietly continuing unencrypted.
> * The database has been updated (schema version 12). Servers,
> groups, articles, filters, identities and drafts are migrated in
> place and nothing is deleted - and if NeReO ever meets a version
> it cannot migrate, it makes a physical copy first and tells you.
> The new structures are not used by anything yet: they are there
> for the trust-and-certificates work that follows in this same
> release. As always before a version that touches the database, a
> backup from Maintenance costs nothing.
> * A restore could give a server a user name it never had. Servers
> with no account were written to the backup correctly, as an empty
> value, but read back as the literal word "null": four characters,
> which NeReO then dutifully tried to log in with, on servers that
> want no login at all. The server answered "381 Enter password",
> NeReO sent an empty password, and the server replied with a syntax
> error that meant nothing to anyone. It was a single missing check
> among seven fields of the same kind, and it had been there since at
> least 1.2.8. Restores are now correct, and any server still
> carrying that fake user name is repaired the first time you restore
> a backup: the message tells you how many.
> * NeReO no longer sends an empty password when a server asks for one.
> It says plainly that no password is saved for that server, and
> suggests clearing the user name if the server does not need an
> account. The check sits where the server actually asked for the
> password (a 381 response): a server that is happy with the user
> name alone answers 281 and keeps working, as RFC 4643 requires.
> * Maintenance has a new "Database diagnostics" panel. It counts the
> rows of every table and shows the schema version and the space
> used, with a Copy button. It exists because a database migration
> that OPENS is not the same as a migration that WORKED: it can be
> formally correct and still have emptied a table, and the app would
> start perfectly - it is the archive that would be missing. Take the
> numbers before an update and again after, and if they match,
> nothing was lost. It is also the quickest thing to attach to a bug
> report. Nothing is computed until you press the button.
> * Replying to a crosspost now shows where the message is actually
> going. Until now the compose screen showed only the group you were
> reading, even when the reply was set to go out on three. Two
> related faults went with it: reopening the group selector to CHECK
> your choice silently reset it to the default (the worst possible
> case, because the act of checking destroyed what was being
> checked), and in the panel layout the crosspost button did not
> exist at all, so changing the groups meant abandoning the reply
> and starting over. All three reported by Dave Royal.
> * "All messages" now works on high-retention servers. Asking for the
> whole history of a very large group made NeReO request the entire
> article range in one go, and the reply could exceed the 64 MB
> ceiling that protects the app from running out of memory: an error,
> and nothing downloaded at all. The overview is now fetched in
> slices, each one saved before the next is asked for. The ceiling
> stays where it was (raising it would have moved the wall, not
> removed it) and there are two bonuses: a sync interrupted halfway
> now resumes instead of starting over, and memory use no longer
> depends on how big the group is. Reported by Bingo3331.
> * TLS trust is now something you grant, not something you are handed.
> The normal path is unchanged. What changes is what happens when it
> FAILS: instead of a dead end, NeReO writes down the identity the
> server showed and marks it SEEN, NOT TRUSTED, and the connection
> still fails. You approve it later, calmly, from Servers -> TLS
> identity, never in a dialog on top of a running sync: a security
> warning that interrupts you is the one you click without reading.
> What is pinned is the SHA-256 of the leaf public key, never an
> intermediate. From then on that key is compared on EVERY
> connection,
> and if it changes NeReO stops and shows you both, with no "accept
> the new one" button. The friction is the feature. There is also a
> per-server "expired certificate" exception that relaxes the dates
> and nothing else, and goes inert by itself the day the server
> renews.
> * "Certificate expires in N days" warning. The trust manager sees the
> certificate on every connection, so the expiry date is free, and
> not
> using it would have been a waste. It comes from a real case: an
> administrator who renews BY HAND, and a Let's Encrypt certificate
> that lives 90 days. That situation is not closed, it is cyclical.
> * Accented text no longer breaks in articles with no character set
> declaration, or with a wrong one. Of seven measured cases, five
> lost
> the text; the worst was the WRONG declaration, which produced no
> error markers at all, just plausible gibberish that NeReO
> re-published in impeccable UTF-8. A three-step rule, ten cases
> checked on every build. And because NeReO stores the ALREADY
> DECODED
> text, there is a new "Reload message" action for the article bar:
> without it the fix would be invisible on everything already in your
> archive.
> * Read follows the Message-ID. A crosspost read in one group counts
> as
> read in the others: it is one message, and it is what MesNews does.
> Watched threads and filters already worked this way; read was the
> odd one out. On by default.
> * Followup-To read and respected. It was the one GNKSA criterion
> NeReO
> did not meet. If the author asks for follow-ups to continue
> elsewhere, the reply goes THERE, and the compose screen SAYS so:
> redirecting without saying it would replace a discourtesy with a
> surprise. If you open the groups selector and choose yourself, your
> choice wins. The "poster" case does not block posting but warns and
> offers the author's address.
> * Quote intro settable per group (asked for by Henry The Mole). It
> REPLACES the one from your identity instead of joining the random
> draw: the point is a deliberate choice, typically the language of
> the group.
>
> --
> .:. MCSM .:.
> -> posting from PC with MesNews <-
--
{gemini,https}://{,rek2.}hispagatos.org - mastodon: @rek2@hispagatos.space
[https|gemini]://2600.Madrid - https://hispagatos.space/@rek2
Reticulum Laptop: lxmf@c6dc6bb3a6b0955d102fde5e7613e2af
Reticulum PC: lxmf@46f7530c35cd9cb2e8e6cf6d39064810
Back to news.software.readers | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here MCSM <despammed@mcsm.anonaddy.me> - 2026-09-17 21:00 +0200
Re: [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here ReK2 Hispagatos <rek2@usenet_reborn.tui> - 2026-09-18 18:32 +0000
Re: [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here MCSM <despammed@mcsm.anonaddy.me> - 2026-09-19 14:40 +0200
Re: [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here Anton Shepelev <anton.txt@gmail.moc> - 2026-09-19 20:05 +0300
csiph-web