• [NeReO 1.4] - Ne(ws) Re(ader) O(pensource) for Android is here

    From MCSM@despammed@mcsm.anonaddy.me to news.software.readers,alt.comp.software.newsreaders,comp.mobile.android on Thu Sep 17 21:00:30 2026
    From Newsgroup: comp.mobile.android

    On SourceForge (or just wait for the notification in the app ;) https://sourceforge.net/projects/nereo/files/1.4/

    This time itrCOs a "MegaUpdate"! ;)

    So, bug fixes only rCo no more new features request, please! ^^

    * STARTTLS now follows both halves of RFC 4642 instead of one. If a
    server REFUSES STARTTLS before the handshake, NeReO may carry on
    unencrypted as the standard allows, and that is unchanged. But if
    the server ACCEPTS (382) and the handshake then fails, RFC 4642
    requires both sides to close the connection - and until 1.3.7
    NeReO carried on in cleartext instead. That fallback was probably
    broken anyway, because the TLS ClientHello had already been
    written to the socket, but the point is that it should never have
    been attempted. Such a connection now fails with an explicit
    message rather than quietly continuing unencrypted.
    * The database has been updated (schema version 12). Servers,
    groups, articles, filters, identities and drafts are migrated in
    place and nothing is deleted - and if NeReO ever meets a version
    it cannot migrate, it makes a physical copy first and tells you.
    The new structures are not used by anything yet: they are there
    for the trust-and-certificates work that follows in this same
    release. As always before a version that touches the database, a
    backup from Maintenance costs nothing.
    * A restore could give a server a user name it never had. Servers
    with no account were written to the backup correctly, as an empty
    value, but read back as the literal word "null": four characters,
    which NeReO then dutifully tried to log in with, on servers that
    want no login at all. The server answered "381 Enter password",
    NeReO sent an empty password, and the server replied with a syntax
    error that meant nothing to anyone. It was a single missing check
    among seven fields of the same kind, and it had been there since at
    least 1.2.8. Restores are now correct, and any server still
    carrying that fake user name is repaired the first time you restore
    a backup: the message tells you how many.
    * NeReO no longer sends an empty password when a server asks for one.
    It says plainly that no password is saved for that server, and
    suggests clearing the user name if the server does not need an
    account. The check sits where the server actually asked for the
    password (a 381 response): a server that is happy with the user
    name alone answers 281 and keeps working, as RFC 4643 requires.
    * Maintenance has a new "Database diagnostics" panel. It counts the
    rows of every table and shows the schema version and the space
    used, with a Copy button. It exists because a database migration
    that OPENS is not the same as a migration that WORKED: it can be
    formally correct and still have emptied a table, and the app would
    start perfectly - it is the archive that would be missing. Take the
    numbers before an update and again after, and if they match,
    nothing was lost. It is also the quickest thing to attach to a bug
    report. Nothing is computed until you press the button.
    * Replying to a crosspost now shows where the message is actually
    going. Until now the compose screen showed only the group you were
    reading, even when the reply was set to go out on three. Two
    related faults went with it: reopening the group selector to CHECK
    your choice silently reset it to the default (the worst possible
    case, because the act of checking destroyed what was being
    checked), and in the panel layout the crosspost button did not
    exist at all, so changing the groups meant abandoning the reply
    and starting over. All three reported by Dave Royal.
    * "All messages" now works on high-retention servers. Asking for the
    whole history of a very large group made NeReO request the entire
    article range in one go, and the reply could exceed the 64 MB
    ceiling that protects the app from running out of memory: an error,
    and nothing downloaded at all. The overview is now fetched in
    slices, each one saved before the next is asked for. The ceiling
    stays where it was (raising it would have moved the wall, not
    removed it) and there are two bonuses: a sync interrupted halfway
    now resumes instead of starting over, and memory use no longer
    depends on how big the group is. Reported by Bingo3331.
    * TLS trust is now something you grant, not something you are handed.
    The normal path is unchanged. What changes is what happens when it
    FAILS: instead of a dead end, NeReO writes down the identity the
    server showed and marks it SEEN, NOT TRUSTED, and the connection
    still fails. You approve it later, calmly, from Servers -> TLS
    identity, never in a dialog on top of a running sync: a security
    warning that interrupts you is the one you click without reading.
    What is pinned is the SHA-256 of the leaf public key, never an
    intermediate. From then on that key is compared on EVERY
    connection,
    and if it changes NeReO stops and shows you both, with no "accept
    the new one" button. The friction is the feature. There is also a
    per-server "expired certificate" exception that relaxes the dates
    and nothing else, and goes inert by itself the day the server
    renews.
    * "Certificate expires in N days" warning. The trust manager sees the
    certificate on every connection, so the expiry date is free, and
    not
    using it would have been a waste. It comes from a real case: an
    administrator who renews BY HAND, and a Let's Encrypt certificate
    that lives 90 days. That situation is not closed, it is cyclical.
    * Accented text no longer breaks in articles with no character set
    declaration, or with a wrong one. Of seven measured cases, five
    lost
    the text; the worst was the WRONG declaration, which produced no
    error markers at all, just plausible gibberish that NeReO
    re-published in impeccable UTF-8. A three-step rule, ten cases
    checked on every build. And because NeReO stores the ALREADY
    DECODED
    text, there is a new "Reload message" action for the article bar:
    without it the fix would be invisible on everything already in your
    archive.
    * Read follows the Message-ID. A crosspost read in one group counts
    as
    read in the others: it is one message, and it is what MesNews does.
    Watched threads and filters already worked this way; read was the
    odd one out. On by default.
    * Followup-To read and respected. It was the one GNKSA criterion
    NeReO
    did not meet. If the author asks for follow-ups to continue
    elsewhere, the reply goes THERE, and the compose screen SAYS so:
    redirecting without saying it would replace a discourtesy with a
    surprise. If you open the groups selector and choose yourself, your
    choice wins. The "poster" case does not block posting but warns and
    offers the author's address.
    * Quote intro settable per group (asked for by Henry The Mole). It
    REPLACES the one from your identity instead of joining the random
    draw: the point is a deliberate choice, typically the language of
    the group.
    --
    .:. MCSM .:.
    posting from PC with MesNews <-
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From ReK2 Hispagatos@rek2@usenet_reborn.tui to news.software.readers,alt.comp.software.newsreaders,comp.mobile.android on Fri Sep 18 18:32:19 2026
    From Newsgroup: comp.mobile.android

    Very nice!! I am telling people about it, it was much needed
    I wrote usenet_reborn for a moderm lite TUI usenet/nntp client
    but have no idea of android things so I am telling everyone
    about Nere0
    any chance you add it to f-droid ?

    Happy Hacking
    ReK2

    [in reply to MCSM <<mn.8cec7ea934007822.0@mcsm.org>>]

    On SourceForge (or just wait for the notification in the app ;) https://sourceforge.net/projects/nereo/files/1.4/

    This time itrCOs a "MegaUpdate"! ;)

    So, bug fixes only rCo no more new features request, please! ^^

    * STARTTLS now follows both halves of RFC 4642 instead of one. If a
    server REFUSES STARTTLS before the handshake, NeReO may carry on
    unencrypted as the standard allows, and that is unchanged. But if
    the server ACCEPTS (382) and the handshake then fails, RFC 4642
    requires both sides to close the connection - and until 1.3.7
    NeReO carried on in cleartext instead. That fallback was probably
    broken anyway, because the TLS ClientHello had already been
    written to the socket, but the point is that it should never have
    been attempted. Such a connection now fails with an explicit
    message rather than quietly continuing unencrypted.
    * The database has been updated (schema version 12). Servers,
    groups, articles, filters, identities and drafts are migrated in
    place and nothing is deleted - and if NeReO ever meets a version
    it cannot migrate, it makes a physical copy first and tells you.
    The new structures are not used by anything yet: they are there
    for the trust-and-certificates work that follows in this same
    release. As always before a version that touches the database, a
    backup from Maintenance costs nothing.
    * A restore could give a server a user name it never had. Servers
    with no account were written to the backup correctly, as an empty
    value, but read back as the literal word "null": four characters,
    which NeReO then dutifully tried to log in with, on servers that
    want no login at all. The server answered "381 Enter password",
    NeReO sent an empty password, and the server replied with a syntax
    error that meant nothing to anyone. It was a single missing check
    among seven fields of the same kind, and it had been there since at
    least 1.2.8. Restores are now correct, and any server still
    carrying that fake user name is repaired the first time you restore
    a backup: the message tells you how many.
    * NeReO no longer sends an empty password when a server asks for one.
    It says plainly that no password is saved for that server, and
    suggests clearing the user name if the server does not need an
    account. The check sits where the server actually asked for the
    password (a 381 response): a server that is happy with the user
    name alone answers 281 and keeps working, as RFC 4643 requires.
    * Maintenance has a new "Database diagnostics" panel. It counts the
    rows of every table and shows the schema version and the space
    used, with a Copy button. It exists because a database migration
    that OPENS is not the same as a migration that WORKED: it can be
    formally correct and still have emptied a table, and the app would
    start perfectly - it is the archive that would be missing. Take the
    numbers before an update and again after, and if they match,
    nothing was lost. It is also the quickest thing to attach to a bug
    report. Nothing is computed until you press the button.
    * Replying to a crosspost now shows where the message is actually
    going. Until now the compose screen showed only the group you were
    reading, even when the reply was set to go out on three. Two
    related faults went with it: reopening the group selector to CHECK
    your choice silently reset it to the default (the worst possible
    case, because the act of checking destroyed what was being
    checked), and in the panel layout the crosspost button did not
    exist at all, so changing the groups meant abandoning the reply
    and starting over. All three reported by Dave Royal.
    * "All messages" now works on high-retention servers. Asking for the
    whole history of a very large group made NeReO request the entire
    article range in one go, and the reply could exceed the 64 MB
    ceiling that protects the app from running out of memory: an error,
    and nothing downloaded at all. The overview is now fetched in
    slices, each one saved before the next is asked for. The ceiling
    stays where it was (raising it would have moved the wall, not
    removed it) and there are two bonuses: a sync interrupted halfway
    now resumes instead of starting over, and memory use no longer
    depends on how big the group is. Reported by Bingo3331.
    * TLS trust is now something you grant, not something you are handed.
    The normal path is unchanged. What changes is what happens when it
    FAILS: instead of a dead end, NeReO writes down the identity the
    server showed and marks it SEEN, NOT TRUSTED, and the connection
    still fails. You approve it later, calmly, from Servers -> TLS
    identity, never in a dialog on top of a running sync: a security
    warning that interrupts you is the one you click without reading.
    What is pinned is the SHA-256 of the leaf public key, never an
    intermediate. From then on that key is compared on EVERY
    connection,
    and if it changes NeReO stops and shows you both, with no "accept
    the new one" button. The friction is the feature. There is also a
    per-server "expired certificate" exception that relaxes the dates
    and nothing else, and goes inert by itself the day the server
    renews.
    * "Certificate expires in N days" warning. The trust manager sees the
    certificate on every connection, so the expiry date is free, and
    not
    using it would have been a waste. It comes from a real case: an
    administrator who renews BY HAND, and a Let's Encrypt certificate
    that lives 90 days. That situation is not closed, it is cyclical.
    * Accented text no longer breaks in articles with no character set
    declaration, or with a wrong one. Of seven measured cases, five
    lost
    the text; the worst was the WRONG declaration, which produced no
    error markers at all, just plausible gibberish that NeReO
    re-published in impeccable UTF-8. A three-step rule, ten cases
    checked on every build. And because NeReO stores the ALREADY
    DECODED
    text, there is a new "Reload message" action for the article bar:
    without it the fix would be invisible on everything already in your
    archive.
    * Read follows the Message-ID. A crosspost read in one group counts
    as
    read in the others: it is one message, and it is what MesNews does.
    Watched threads and filters already worked this way; read was the
    odd one out. On by default.
    * Followup-To read and respected. It was the one GNKSA criterion
    NeReO
    did not meet. If the author asks for follow-ups to continue
    elsewhere, the reply goes THERE, and the compose screen SAYS so:
    redirecting without saying it would replace a discourtesy with a
    surprise. If you open the groups selector and choose yourself, your
    choice wins. The "poster" case does not block posting but warns and
    offers the author's address.
    * Quote intro settable per group (asked for by Henry The Mole). It
    REPLACES the one from your identity instead of joining the random
    draw: the point is a deliberate choice, typically the language of
    the group.

    --
    .:. MCSM .:.
    posting from PC with MesNews <-
    --
    {gemini,https}://{,rek2.}hispagatos.org - mastodon: @rek2@hispagatos.space [https|gemini]://2600.Madrid - https://hispagatos.space/@rek2 Reticulum Laptop: lxmf@c6dc6bb3a6b0955d102fde5e7613e2af
    Reticulum PC: lxmf@46f7530c35cd9cb2e8e6cf6d39064810
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From MCSM@despammed@mcsm.anonaddy.me to news.software.readers,alt.comp.software.newsreaders,comp.mobile.android on Sat Sep 19 14:40:53 2026
    From Newsgroup: comp.mobile.android

    On 18/09/2026 , *ReK2 Hispagatos* wrote:
    .....
    any chance you add it to f-droid ?

    Nope! Not by my side.
    Maybe some other people can do this.
    I.E. Henry The Mole, another Italian usenet fan, is working on a
    possible fork. He is also a fan of F-Droid and Open Source apps for
    Android
    Have a look here: https://www.themolezone.com/en

    PS: Please, in the future, try to avoid replying above the text of a
    message. (Top posting)

    If you think about it, it breaks the natural flow of reading.
    For any given topic, it is better to continue writing below
    the quoted text, following the natural reading order. ;)

    Otherwise:

    the quoted text, following the natural reading order. ;)
    For any given topic, it is better to continue writing below
    If you think about it, it breaks the natural flow of reading.
    --
    .:. MCSM .:.
    posting from PC with MesNews <-
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Anton Shepelev@anton.txt@gmail.moc to news.software.readers,alt.comp.software.newsreaders,comp.mobile.android on Sat Sep 19 20:05:10 2026
    From Newsgroup: comp.mobile.android

    MCSM:

    Please, in the future, try to avoid replying above the
    text of a message. (Top posting)

    Because it messes up the flow of reading.
    How come?
    I prefer to reply inline.
    What do you do instead?
    No.
    Do you like top-posting?
    -- <https://academickids.com/encyclopedia/index.php/Top-posting>
    --
    () ascii ribbon campaign -- against html e-mail
    /\ www.asciiribbon.org -- against proprietary attachments
    --- Synchronet 3.22a-Linux NewsLink 1.2