ANNOUNCE: fetchmail 6.5.0 is available (modernization)
Matthias Andree via Fetchmail-announce <[email protected]> Tue, 29 Oct 2024 23:10:46 +0100
| Newsgroups | gmane.mail.fetchmail.announce |
|---|---|
| Message-ID | <ZyFdZvtZwBBIRA23__15914.8550754011$1730239898$gmane$org@ryzen.an3e.de> |
--===============9212218406824930763==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature"; boundary="HtbRGin+CBh1Sp5Q"
Content-Disposition: inline
--HtbRGin+CBh1Sp5Q
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
The 6.5.0 release of fetchmail is now available at the usual locations,
including <https://downloads.sourceforge.net/project/fetchmail/branch_6.5/>.
The source archive is available at:
<https://downloads.sourceforge.net/project/fetchmail/branch_6.5/fetchmail-6=
=2E5.0.tar.xz/download>
The detached GnuPG signature is available at:
<https://downloads.sourceforge.net/project/fetchmail/branch_6.5/fetchmail-6=
=2E5.0.tar.xz.asc/download>
The SHA256 hashes for the tarballs are:
SHA2-256(fetchmail-6.5.0.tar.xz)=3D 42611aea4861a5311e5116843f01c203dceadf4=
40bf2eb1b4a43a445f2977668
Note that the Sourceforge Git view is quirky,
the preferred Git repository is at=20
https://gitlab.com/fetchmail/fetchmail
and mirrored at =20
https://sourceforge.net/p/fetchmail/git/ci/legacy_6x/tree/
But it seems that SourceForge's Git web interface isn't fully=20
recognizing the latest changes on the "legacy_6x" branch that the 6.5.0=20
release was made from, you need to click the 6.5.0 tag on the left to=20
see the update version.
Fetchmail 6.4.X and older releases are now unsupported.
DISTRIBUTORS BEWARE: OpenSSL changed license, so you may need to change
your license tags and possibly the license which you invoke to=20
redistribute fetchmail. As an alternative, wolfSSL could be used
to maintain GPL v2 compatibility, but it lacks some features OpenSSL=20
offers.
Here are the release notes:
---------------------------------------------------------------------------=
-----
fetchmail-6.5.0 (released 2024-10-29, 31200 LoC):
## SECURITY FIX:
* .netrc now may not have more than 0700 permission if it contains password=
s,
else fetchmail will warn and ignore the file.
## REMOVED FEATURES
* fetchmail no longer supports using an MDA as SMTP fallback. This is requi=
red=20
to make deliveries consistent.
The --enable-fallback configure option is gone.
* fetchmail no longer supports SSLv3. --sslproto ssl3 and ssl3+ options have
been removed and behave as though "--sslproto auto" had been given.
## INCOMPATIBLE CHANGES
* fetchmail by default only negotiates TLS v1.2 or higher. (RFC-7525)
* fetchmail can auto-negotiate TLS v1.1 through the --sslproto tls1.1+ opti=
on.
* fetchmail can auto-negotiate TLS v1.0 through the --sslproto tls1+ option.
* fetchmailconf now requires Python 3.7.0 or newer.
* fetchmail, with --logfile, now logs time stamps into the file, in localti=
me
and in the format "Jun 20 23:45:01 fetchmail: ". It will be localized thr=
ough
the environment variables LC_TIME (or LC_ALL) and TZ.
Contributed by Holger Hoffst=E4tte.
* fetchmail sets the OPENSSL security level to 2 by default.
Override is possible from an environment variable,
see EXPERIMENTAL CHANGES below.
* The ca, da, en_GB, id, it, nl, ru, zh_CN translations have been disabled,
they are too far behind.
## CHANGED REQUIREMENTS
* fetchmail 6.5.0 is written in C99 and requires a SUSv3 (Single Unix
Specification v3, a superset of POSIX.1-2001 aka. IEEE Std 1003.1-2001 wi=
th
XSI extension) compliant system.
In particular, older fetchmail versions had workarounds or replacement co=
de
for several functions standardized in the Single Unix Specification v3, t=
hese
have been removed. Hence:
- The trio/ library has been removed from the distribution.
- The libesmtp/getaddrinfo.? library has been removed from the distributi=
on.
- The KAME/getnameinfo.c file has been removed from the distribution.
* fetchmail 6.5.0 requires a TLSv1.3-capable version of OpenSSL or wolfSSL,
at a minimum OpenSSL v3.0.9 or wolfSSL v5.7.2.
## TRANSLATIONS: fetchmail's messages were translated by these fine people:
* cs: Petr Pisar [Czech]
* eo: Keith Bowes [Esperanto]
* es: Cristian Oth=F3n Mart=EDnez Vera [Spanish]
* fr: Fr=E9d=E9ric Marchal [French]
* ja: Takeshi Hamasaki [Japanese]
* ro: Remus-Gabriel Chelu [Romanian]
* sv: G=F6ran Uddeborg [Swedish]
* sq: Besnik Bleta [Albanian]
* pl: Jakub Bogusz [Polish]
## BUG FIXES
* fetchmail can now report mailbox sizes of 2^31 octets and beyond (2 GibiB=
).
This required C99 support (for the long long type).
Fixes Debian Bug#873668, reported by Andreas Schmidt.
* fetchmail now defines its OpenSSL API level to 3.0.0 so as to expose the
3.0.0 APIs from OpenSSL.
* The .netrc parser no longer permits "machine" after "default".
* Add manpage info on the .netrc syntax, as ftp(1) is not standardized and
may not be installed. Fixes Launchpad Bug #1976361 reported by Bill Yikes.
* Received: lines now return GMT time if the tzoffset cannot be represented
as whole minutes. Reported by @rriddicc via Gitlab #49.
* If fetchmail was running localized, generated an error e-mail message loc=
ally,
and if the selected translation would require the Subject: line to wrap
inside an RFC-2047 encoded word (=3D?UTF-8?Q?...?=3D), the wrapped encode=
d-word
was not indented, thus not marked as a continuation line.
* SSL error handling was improved, fetchmail now consistently clears the
thread/SSL error queue before SSL I/O operations and checks SSL_get_error
afterwards. The SSL_connect() error handling has been revised to log more
consistently.
## CHANGES
* When fetchmail attempts to log out from an IMAP4 server and the server me=
sses
up its responses (it is supposed to send an untagged * BYE and a tagged
A4711 OK) and sends a tagged A4711 BYE response, tolerate that, rather th=
an
reporting a protocol error. We don't intend to chat any more so the proto=
col
violation is harmless, and we know the server cannot send more untagged
status responses.
Analysis and fix courtesy of Maciej S. Szmigiero, GitLab merge request !2=
0.
* The configure script now spends more effort for getting --with-ssl right,=
by
running pkg-config in the right environment, and using the AC_LIB_LINKFLA=
GS
macro to obtain run-time library path setting flags.
* For typical POP3/IMAP ports 110, 143, 993, 995, if port and --ssl option
do not match, emit a warning and continue. Closes Gitlab #31.
* There is now a --idletimeout feature contributed by Eric Durand, to
permit setting a shorter timeout for the --idle option, because many
servers violate the protocol (requiring 30 minutes) and hang up sooner th=
an
the 28 minutes fetchmail waits before refreshing IDLE.
GitLab merge request !35.
* There is now a --forceidle feature to force idle mode even if not adverti=
sed
in the server capabilities. This is a dangerous option, use it carefully.
Courtesy of Eric Durand, GitLab merge request !39.
* There is now a --moveto feature (only feasible in IMAP) that, instead of
flushing mail, moves it to a user-specified folder. This is to assist with
archiving, or when providers (G...) break the IMAP model.
Courteously provided by Damjan Jovanovic.
* rcfile parsing errors are now reported in more detail, and with -vv mode,
also lead to a non-importable Python dump of what was obtained, for debug=
ging.
* fetchmail's --auth option ssh was renamed to implicit, to make clear that=
it
does *NOT* imply any particular type or features of the --plugin. --auth=
ssh
will be understood for a while for compatibility but fetchmail will repor=
t it
as implicit.
* fetchmail no longer warns about port/service mismatches with/without ssl
option when a "plugin" is in use because fetchmail cannot know whether the
plugin talks SSL or STARTTLS/STLS. Fixes Debian Bug#1076604.
* fetchmail re-executes itself if the .netrc file's modification change
is found to be newer at the beginning of a new run.
* fetchmail can now use other digest algorithms than MD5 for the
--sslfingerprint option. To use, specify the algorithm's name in
curly braces as prefix in the finger print, say,
--sslfingerprint '{SHA256}00:01:[...]:1F'. This will also switch the
algorithm for printing. All algorithms supported by the TLS/SSL library
can be specified. Fixes Gitlab issue #19, Debian Bug#700266.
## EXPERIMENTAL CHANGES - these are not documented anywhere else, only here:
* fetchmail supports a FETCHMAIL_SSL_SECLEVEL environment variable that
can be used to override the OpenSSL security level. Fetchmail by default
raises the security level to 2 if lower. This variable can be used to low=
er it.
Use with extreme caution. Note that levels 3 or higher will frequently ca=
use
incompabilities with servers because server-side data sizes are often too=
low.
Valid range: 0 to 5 for OpenSSL 1.1.1 and 3.0.
* fetchmail supports a FETCHMAIL_SSL_CIPHERS environment variable that
sets the cipher string (through two different OpenSSL functions) for SSL =
and
TLS versions up to TLSv1.2.
If setting the ciphers fails, fetchmail will not connect.
If not given, defaults to Postfix's "medium" list,
"aNULL:-aNULL:HIGH:MEDIUM:+RC4:@STRENGTH".
* fetchmail supports a FETCHMAIL_TLS13_CIPHERSUITES environment variable
that sets the ciphersuites (a colon-separated list, without + ! -) for
TLSv1.3. If not given, defaults to OpenSSL's built-in list. If setting the
ciphersuites fails, fetchmail refuses to connect.
* NOTE the features above are simplistic. For instance, even though you
configure --sslproto tls1.3, a failure to set tls1.2 ciphers could cause
a connection abort.
* fetchmail can be built with meson 1.30 or newer <https://mesonbuild.com/>.
fetchmail is not currently written in a way that supports unity
(amalgamated) builds.
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D
--HtbRGin+CBh1Sp5Q
Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE3EplW9mTzUhx+oIQ5BKxVu/zhVoFAmchXWIACgkQ5BKxVu/z
hVojRw//TWMJk2baekLq93+oE00RVRBtKLteKGrGNLbkUYgX0DJGtNRqKjBFq6pm
9NzouNA6P2Bkv/OuJK2qdfNp4FbxJg7Xyjo7OAVOQ/h9cAmkX9R3E0Th5QFttROG
rXmkPR2qNAI5dobaWR7o2CYGUyN9YHAG+mE4sKODbO0ZDCyCfGCFO9NDcNq7Ockg
KGV8cnZmDDwtWOeYt/jrCdLCvqVFjU8D0MDGIOAAoo57K3hR+Qkii+8imE3tp9Ah
HeA50QskOw1j19AesErOkIEYF3plxVhkxA7m53DaKw4b2KLWVGkdNFKNQ2gyXYXP
G6613/a4FVo1pPByVYOlccvDUAqsDNLzkRLdDiKF6HiM4yGcjhhNuHQ35WLZ10xJ
BvkfunFnqT8+HrLttS+Q2TUoMsN1VG6prx/FT853+TD5Rt/1WsjOgcYM8rFjwI4w
JZChA41asQXwfwg0Zjqrml1WKEtH2nWuZSoOomp3h3s1Gu1y0QUSZVVD9UotBwqK
Tdk4QXTPc6bm/8AGDMu3Ya5DxagWT3voDxxrEGDkPOSbGlPUpvM0UKNQsbyWwHut
6mGCgHBrHUS/X3cci1ZY5eZL4IQpVgYS2UHtJPEETQKrqZDfAB9Tgvq+D/zXezMu
wQCXjTKqhqHjRSfqttFr5ONLzX3rjHusq7c8FiAW0p2ckFmZJvU=
=lPWH
-----END PGP SIGNATURE-----
--HtbRGin+CBh1Sp5Q--
--===============9212218406824930763==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============9212218406824930763==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Fetchmail-announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/fetchmail-announce
--===============9212218406824930763==--