Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Bernard Quatermass

@bernardq@ehlo.exim.org
mastodon 4.5.19
  • Open on ehlo.exim.org

A sysadmin for some servers in the exim project. Adversarial analysis and improvement advocate.

0 Followers
0 Following
4 Posts
Joined January 04, 2024
Open post
Bernard Quatermass @bernardq@ehlo.exim.org
· 3mo ago

Forthcoming changes to the Exim Project contribution, security reporting and release procedures.

We are updating our contribution, security reporting and release procedures to better align with the new landscape of development and reporting.

These will be incorporated into the appropriate document locations in due course.

----

Contributing

As a mature project we do not expect major changes in the current codebase. Most changes are likely to be limited to security/bug fixes, refactoring for code consistency and very occasionally new capabilities to accomodate new standards (example as of today being the forthcoming DKIM2 specification).

Any sizeable contribution will be considered not only in respect to its conformity with current project standards but also in terms of whether the project developers consider the ongoing maintenance burden to be acceptable.

With this in mind we would ask you follow the following steps to contribute.

* Start by checking and discussing via the exim-user mailing list whether we would consider the feature.
* If we approve an suitable ticket will be created to track the specifics.
* We do not accept LLM generated content in any form whatsoever.

----

Security Reports

* We only accept reports against the latest release.
* Reports should be limited to succinct descriptions of the problem, with minimal code inclusion.
* Reports where EXPERIMENTAL builds flags are used must be filed as ordinary bugs and are not considered security issues.
* Reports against isolated source files builds are not accepted. Only reports against the full binary are considered.
* Do not include Proof of Concepts
* Do not include suggested patches.
* Do not include extended diatribes about code flow.
* Reports we believe are LLM generated will either be rejected outright or if thought to be plausible will be credited to the unnamed and uncredited authors whose works were ingested as the training corpus.
* Reports that do not meet the criteria for security issues but are merely bugs will be turned into normal public issues.
* If we do determine there is a security issue then we will release an update on the relevant branch as soon as there is a tested fix. Each issue will be allocated a GCVE identifier against our GNA ID, we will no longer be using legacy CVE IDs.

----

Release Procedures

We will be changing some of our release procedures. Starting with 4.100 we will change to releasing only 4.yy and 4.yy.zz releases on the master branch.
Intermediate work such as general bug fixing and feature enhancement will move to the 4.next branch.

We will endeavour to apply any .zz security fixes to the 4.next branch in a timely manner though there may be some lag.
Release candidates for 4.yy+1 will be tagged on the 4.next branch.

----

These changes will allow us to allocate our limited resources more efficiently within the current environment. Whilst we might fine-tune some of these changes we will not envisage any significant changes.

62
2
36
5
Open post
Bernard Quatermass @bernardq@ehlo.exim.org
· 1mo ago

RE: @announce@ehlo.exim.org

So, it's finally out.

Includes my favourite new feature that makes blocking stuff easier;

1. Lookups "psl" and "regdom" for, respectively, the public suffix or the registered domain, given a domain and a Public Suffix List file.

Also nice to finally be able to cull some sizeable chunks of antique code, and looking forward to culling more in the next release.

ehlo.exim.org
6
0
5
0
Open post
Bernard Quatermass @bernardq@ehlo.exim.org
· 3mo ago

@gcve@social.circl.lu Hi, in case you weren't aware, it’s a little hard to mail you when your email servers are down/unreachable.

1
0
0
0
Open post
Bernard Quatermass @bernardq@ehlo.exim.org
· 3mo ago
Replying to
@pixelunion@mastodon.social
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 08:24:22 UTC