Re: Retiring lpr and lpd
Slawa Olhovchenkov <[email protected]> Sat, 21 Feb 2026 13:37:44 +0300
| Newsgroups | gmane.os.freebsd.architechture |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Feb 20, 2026 at 10:17:03PM +0100, Robert Clausecker wrote: > Hi Steve, > > Am Fri, Feb 20, 2026 at 01:12:55PM -0800 schrieb Steve Kargl: > > Did you miss the "What is the problem? Don't fix what isn't > > broken." I've been using lp* since I've started using > > 386BSD+patchkit some 3 decades ago. The ability to set up > > printing without the idiosyncrasy of the ports collections > > is a blessing. > > > > > What's worse, most of them are setugid, and lpd(8) is a network-facing > > > daemon with> IP-based authentication and little to no input validation. > > > > Is there an open CVE that we need to worry about? > > > > Furthermore, > > > better-maintained alternatives are available from ports: print/lprng is > > > a drop-in replacement derived from the same code base, while print/cups > > > provides far more functionality and a compatible command-line interface. > > > > Better alternative are available for many things that are installed > > as part of a FreeBSD base distribution (e.g., editors and shells). > > Should remove all of those things as well? > > The deprecation is planned because the codebase is a pile of crap exposed > to the internet. We can keep them around if someone volunteers to clean > up. Given that there seem to be a few users of these tools in the project, > it should not be too hard to find someone willing to step forwards. Maybe > you? Just change default for lpd to run w/ -s key.