Re: lpd: the thin edge of the wedge?
"Julian H. Stacey" <[email protected]> Fri, 27 Feb 2026 01:17:40 +0100
| Newsgroups | gmane.os.freebsd.architechture |
|---|---|
| Organization | http://berklix.com/jhs/ |
| Message-ID | <[email protected]> |
Thu, 26 Feb 2026 15:49:58 +0100 =3D?utf-8?Q?Dag-Erling_Sm=3DC3=3DB8rgrav?=3D= <[email protected]> wrote: =3D?utf-8?Q?Dag-Erling_Sm=3DC3=3DB8rgrav?=3D wrote: > "Julian H. Stacey" <[email protected]> writes: > > Old simple small lpr/lpd code that compiles & runs should not be remov= ed, > > it would gratuitously disrupt small users (*). Those who dont > > want to further maintain aka enhance it, best stop work, not remove it= . > > These programs are setuid root=C2=B9 and can't work without it. If ther= e is a > buffer overflow in one of them, you are cooked. > > =C2=B9 except lpd(8), but it's a daemon that runs as root and accepts > connections from anyone over a Unix socket, plus parses any file that > any local user deposits in the spool using lpr(1). Thanks. That would help, appended as BUGS to man 9 lpd {& lpr maybe] https://man.freebsd.org/cgi/man.cgi?query=3Dlpd&manpath=3DFreeBSD+15.0-REL= EASE+and+Ports lpd [-s] is OK for me behind a firewall, no untrusted users & machines. ( Risk of buffers doesn't worry me, lpd from '86 hasn't burnt me (though I've chased hardware buffer corruption in '96 http://www.berklix.com/~jhs/hardware/1542a/ ) Please avoid forced removal, disruption for no benefit for some: I've been under ongoing multiple real world deadline distractions for way over a year, & no time to waste to just resurect code in use. There'll be others busier still, no time for mail lists, who must groan each time FreeBSD chops code, obstructing upgrades & making some wonder if it would be easier on a less volatile BSD. Cheers, -- = Julian Stacey http://berklix.com/jhs/mail/ Can't reply to Gmail & Yahoo. Arm Ukraine. Contraception & plain text email to reduce global warming.