Re: Retiring lpr and lpd

Slawa Olhovchenkov <[email protected]> Sat, 21 Feb 2026 13:37:44 +0300
Newsgroups gmane.os.freebsd.architechture
Message-ID <[email protected]>
On Fri, Feb 20, 2026 at 10:17:03PM +0100, Robert Clausecker wrote:

> Hi Steve,
> 
> Am Fri, Feb 20, 2026 at 01:12:55PM -0800 schrieb Steve Kargl:
> > Did you miss the "What is the problem? Don't fix what isn't
> > broken."  I've been using lp* since I've started using
> > 386BSD+patchkit some 3 decades ago.  The ability to set up
> > printing without the idiosyncrasy of the ports collections
> > is a blessing.
> > 
> > > What's worse, most of them are setugid, and lpd(8) is a network-facing
> > > daemon with> IP-based authentication and little to no input validation.
> > 
> > Is there an open CVE that we need to worry about?
> > 
> >   Furthermore,
> > > better-maintained alternatives are available from ports: print/lprng is
> > > a drop-in replacement derived from the same code base, while print/cups
> > > provides far more functionality and a compatible command-line interface.
> > 
> > Better alternative are available for many things that are installed
> > as part of a FreeBSD base distribution (e.g., editors and shells).
> > Should remove all of those things as well?
> 
> The deprecation is planned because the codebase is a pile of crap exposed
> to the internet.  We can keep them around if someone volunteers to clean
> up.  Given that there seem to be a few users of these tools in the project,
> it should not be too hard to find someone willing to step forwards.  Maybe
> you?

Just change default for lpd to run w/ -s key.