Re: lpd: the thin edge of the wedge?

"Julian H. Stacey" <[email protected]> Fri, 27 Feb 2026 01:17:40 +0100
Newsgroups gmane.os.freebsd.architechture
Organization http://berklix.com/jhs/
Message-ID <[email protected]>
Thu, 26 Feb 2026 15:49:58 +0100 =3D?utf-8?Q?Dag-Erling_Sm=3DC3=3DB8rgrav?=3D=
 <[email protected]> wrote:

=3D?utf-8?Q?Dag-Erling_Sm=3DC3=3DB8rgrav?=3D wrote:
> "Julian H. Stacey" <[email protected]> writes:
> > Old simple small lpr/lpd code that compiles & runs should not be remov=
ed,
> > it would gratuitously disrupt small users (*).  Those who dont
> > want to further maintain aka enhance it, best stop work, not remove it=
.
>
> These programs are setuid root=C2=B9 and can't work without it.  If ther=
e is a
> buffer overflow in one of them, you are cooked.
>
> =C2=B9 except lpd(8), but it's a daemon that runs as root and accepts
>   connections from anyone over a Unix socket, plus parses any file that
>   any local user deposits in the spool using lpr(1).

Thanks. That would help, appended as BUGS to man 9 lpd {& lpr maybe]
https://man.freebsd.org/cgi/man.cgi?query=3Dlpd&manpath=3DFreeBSD+15.0-REL=
EASE+and+Ports

lpd [-s] is OK for me behind a firewall, no untrusted users &
machines.  ( Risk of buffers doesn't worry me, lpd from '86 hasn't
burnt me (though I've chased hardware buffer corruption in '96
http://www.berklix.com/~jhs/hardware/1542a/ )

Please avoid forced removal, disruption for no benefit for some:
  I've been under ongoing multiple real world deadline distractions for
  way over a year, & no time to waste to just resurect code in use.
  There'll be others busier still, no time for mail lists, who must
  groan each time FreeBSD chops code, obstructing upgrades
  & making some wonder if it would be easier on a less volatile BSD.

Cheers,
-- =

Julian Stacey  http://berklix.com/jhs/mail/  Can't reply to Gmail & Yahoo.
Arm Ukraine.  Contraception & plain text email to reduce global warming.