Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > news.software.readers > #37799

[NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here

Subject [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here
From MCSM <despammed@mcsm.anonaddy.me>
Newsgroups news.software.readers, alt.comp.software.newsreaders, comp.mobile.android
Message-ID <mn.8cec7ea934007822.0@mcsm.org> (permalink)
Organization mcsm.org
Date 2026-09-17 21:00 +0200

Cross-posted to 3 groups.

Show all headers | View raw


On SourceForge (or just wait for the notification in the app ;)
https://sourceforge.net/projects/nereo/files/1.4/

This time it’s a "MegaUpdate"! ;)

So, bug fixes only — no more new features request, please! ^^

* STARTTLS now follows both halves of RFC 4642 instead of one. If a
    server REFUSES STARTTLS before the handshake, NeReO may carry on
    unencrypted as the standard allows, and that is unchanged. But if
    the server ACCEPTS (382) and the handshake then fails, RFC 4642
    requires both sides to close the connection - and until 1.3.7
    NeReO carried on in cleartext instead. That fallback was probably
    broken anyway, because the TLS ClientHello had already been
    written to the socket, but the point is that it should never have
    been attempted. Such a connection now fails with an explicit
    message rather than quietly continuing unencrypted.
  * The database has been updated (schema version 12). Servers,
    groups, articles, filters, identities and drafts are migrated in
    place and nothing is deleted - and if NeReO ever meets a version
    it cannot migrate, it makes a physical copy first and tells you.
    The new structures are not used by anything yet: they are there
    for the trust-and-certificates work that follows in this same
    release. As always before a version that touches the database, a
    backup from Maintenance costs nothing.
  * A restore could give a server a user name it never had. Servers
    with no account were written to the backup correctly, as an empty
    value, but read back as the literal word "null": four characters,
    which NeReO then dutifully tried to log in with, on servers that
    want no login at all. The server answered "381 Enter password",
    NeReO sent an empty password, and the server replied with a syntax
    error that meant nothing to anyone. It was a single missing check
    among seven fields of the same kind, and it had been there since at
    least 1.2.8. Restores are now correct, and any server still
    carrying that fake user name is repaired the first time you restore
    a backup: the message tells you how many.
  * NeReO no longer sends an empty password when a server asks for one.
    It says plainly that no password is saved for that server, and
    suggests clearing the user name if the server does not need an
    account. The check sits where the server actually asked for the
    password (a 381 response): a server that is happy with the user
    name alone answers 281 and keeps working, as RFC 4643 requires.
  * Maintenance has a new "Database diagnostics" panel. It counts the
    rows of every table and shows the schema version and the space
    used, with a Copy button. It exists because a database migration
    that OPENS is not the same as a migration that WORKED: it can be
    formally correct and still have emptied a table, and the app would
    start perfectly - it is the archive that would be missing. Take the
    numbers before an update and again after, and if they match,
    nothing was lost. It is also the quickest thing to attach to a bug
    report. Nothing is computed until you press the button.
  * Replying to a crosspost now shows where the message is actually
    going. Until now the compose screen showed only the group you were
    reading, even when the reply was set to go out on three. Two
    related faults went with it: reopening the group selector to CHECK
    your choice silently reset it to the default (the worst possible
    case, because the act of checking destroyed what was being
    checked), and in the panel layout the crosspost button did not
    exist at all, so changing the groups meant abandoning the reply
    and starting over. All three reported by Dave Royal.
  * "All messages" now works on high-retention servers. Asking for the
    whole history of a very large group made NeReO request the entire
    article range in one go, and the reply could exceed the 64 MB
    ceiling that protects the app from running out of memory: an error,
    and nothing downloaded at all. The overview is now fetched in
    slices, each one saved before the next is asked for. The ceiling
    stays where it was (raising it would have moved the wall, not
    removed it) and there are two bonuses: a sync interrupted halfway
    now resumes instead of starting over, and memory use no longer
    depends on how big the group is. Reported by Bingo3331.
  * TLS trust is now something you grant, not something you are handed.
    The normal path is unchanged. What changes is what happens when it
    FAILS: instead of a dead end, NeReO writes down the identity the
    server showed and marks it SEEN, NOT TRUSTED, and the connection
    still fails. You approve it later, calmly, from Servers -> TLS
    identity, never in a dialog on top of a running sync: a security
    warning that interrupts you is the one you click without reading.
    What is pinned is the SHA-256 of the leaf public key, never an
    intermediate. From then on that key is compared on EVERY 
connection,
    and if it changes NeReO stops and shows you both, with no "accept
    the new one" button. The friction is the feature. There is also a
    per-server "expired certificate" exception that relaxes the dates
    and nothing else, and goes inert by itself the day the server
    renews.
  * "Certificate expires in N days" warning. The trust manager sees the
    certificate on every connection, so the expiry date is free, and 
not
    using it would have been a waste. It comes from a real case: an
    administrator who renews BY HAND, and a Let's Encrypt certificate
    that lives 90 days. That situation is not closed, it is cyclical.
  * Accented text no longer breaks in articles with no character set
    declaration, or with a wrong one. Of seven measured cases, five 
lost
    the text; the worst was the WRONG declaration, which produced no
    error markers at all, just plausible gibberish that NeReO
    re-published in impeccable UTF-8. A three-step rule, ten cases
    checked on every build. And because NeReO stores the ALREADY 
DECODED
    text, there is a new "Reload message" action for the article bar:
    without it the fix would be invisible on everything already in your
    archive.
  * Read follows the Message-ID. A crosspost read in one group counts 
as
    read in the others: it is one message, and it is what MesNews does.
    Watched threads and filters already worked this way; read was the
    odd one out. On by default.
  * Followup-To read and respected. It was the one GNKSA criterion 
NeReO
    did not meet. If the author asks for follow-ups to continue
    elsewhere, the reply goes THERE, and the compose screen SAYS so:
    redirecting without saying it would replace a discourtesy with a
    surprise. If you open the groups selector and choose yourself, your
    choice wins. The "poster" case does not block posting but warns and
    offers the author's address.
  * Quote intro settable per group (asked for by Henry The Mole). It
    REPLACES the one from your identity instead of joining the random
    draw: the point is a deliberate choice, typically the language of
    the group.

-- 
          .:. MCSM .:.
-> posting from PC with MesNews <-

Back to news.software.readers | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

[NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here MCSM <despammed@mcsm.anonaddy.me> - 2026-09-17 21:00 +0200
  Re: [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here ReK2 Hispagatos <rek2@usenet_reborn.tui> - 2026-09-18 18:32 +0000
    Re: [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here MCSM <despammed@mcsm.anonaddy.me> - 2026-09-19 14:40 +0200
      Re: [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here Anton Shepelev <anton.txt@gmail.moc> - 2026-09-19 20:05 +0300

csiph-web