Re: Retiring lpr and lpd

Robert Clausecker <[email protected]> Fri, 20 Feb 2026 22:17:03 +0100
Newsgroups gmane.os.freebsd.architechture
Message-ID <[email protected]>
Hi Steve,

Am Fri, Feb 20, 2026 at 01:12:55PM -0800 schrieb Steve Kargl:
> Did you miss the "What is the problem? Don't fix what isn't
> broken."  I've been using lp* since I've started using
> 386BSD+patchkit some 3 decades ago.  The ability to set up
> printing without the idiosyncrasy of the ports collections
> is a blessing.
> 
> > What's worse, most of them are setugid, and lpd(8) is a network-facing
> > daemon with> IP-based authentication and little to no input validation.
> 
> Is there an open CVE that we need to worry about?
> 
>   Furthermore,
> > better-maintained alternatives are available from ports: print/lprng is
> > a drop-in replacement derived from the same code base, while print/cups
> > provides far more functionality and a compatible command-line interface.
> 
> Better alternative are available for many things that are installed
> as part of a FreeBSD base distribution (e.g., editors and shells).
> Should remove all of those things as well?

The deprecation is planned because the codebase is a pile of crap exposed
to the internet.  We can keep them around if someone volunteers to clean
up.  Given that there seem to be a few users of these tools in the project,
it should not be too hard to find someone willing to step forwards.  Maybe
you?

Yours,
Robert Clausecker

-- 
()  ascii ribbon campaign - for an encoding-agnostic world
/\  - against html email  - against proprietary attachments