Re: Retiring lpr and lpd

Warner Losh <[email protected]> Thu, 26 Feb 2026 18:11:12 -0700
Newsgroups gmane.os.freebsd.architechture
Message-ID <CANCZdfovc3pfj8_q8UqkcdckjNnKEU-NWfQMV=xpBX8d8L7Arg@mail.gmail.com>
--0000000000006d7bfb064bc3ead8
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Thu, Feb 26, 2026 at 1:22=E2=80=AFPM Shawn Webb <shawn.webb@hardenedbsd.=
org>
wrote:

> With that said, a random idea poppped in my head. I'm not advocating
> for the idea, I'm simply hoping to convey the idea.
>
> What if the lpr/lpd (and related?) components (I'm just gonna say lpr
> from now on to be brief, but please understand I mean any/all
> components involved) are separated out to a wholly separate git repo
> (specific to lpr).
>
> This repo would be self-contained and buildable as an out-of-tree
> component. So you'd have your BSD-flavor Makefiles that use the normal
> bsd.lib.mk, bsd.prog.mk, (and bsd.*.mk, ...).
>

This is what Cy was advocating. We have a dozen or so moved from base
to ports repos on our freebsd github that have done just that.


> Then, a separate discussion can be held whether to generate a new
> ports entry. This at least gets the components out of base, but usable
> for those users who need ;it. Users could clone the repo, cd to it,
> and `make install` it).
>

And also submit pull requests and show that people care enough to carry
the lpr/lpd water.

I'd lean towards having it as a port because within its security model,
which is admittedly weak, it works. Heck, we have telnetd as a port
which also has a problematical security model...


> This would provide a middle-ground, where a piece of software that is
> known to be problematic is still useable, but not via normal channels.
> Operators would be explicitly opting into lpr.
>

Yea, pkg install freebsd-lpr is a strong opt-in statement without being
burdensome.

Warner


> Thanks,
>
> --
> Shawn Webb
> Cofounder / Security Engineer
> HardenedBSD
>
> Signal Username:  shawn_webb.74
> Tor-ified Signal: +1 303-901-1600 / shawn_webb_opsec.50
>
> https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/raw/master/Shawn_Webb/0=
3A4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc
>

--0000000000006d7bfb064bc3ead8
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g=
mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, Feb 26,=
 2026 at 1:22=E2=80=AFPM Shawn Webb &lt;<a href=3D"mailto:shawn.webb@harden=
edbsd.org">[email protected]</a>&gt; wrote:<br></div><blockquote c=
lass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px soli=
d rgb(204,204,204);padding-left:1ex">With that said, a random idea poppped =
in my head. I&#39;m not advocating<br>
for the idea, I&#39;m simply hoping to convey the idea.<br>
<br>
What if the lpr/lpd (and related?) components (I&#39;m just gonna say lpr<b=
r>
from now on to be brief, but please understand I mean any/all<br>
components involved) are separated out to a wholly separate git repo<br>
(specific to lpr).<br>
<br>
This repo would be self-contained and buildable as an out-of-tree<br>
component. So you&#39;d have your BSD-flavor Makefiles that use the normal<=
br>
<a href=3D"http://bsd.lib.mk" rel=3D"noreferrer" target=3D"_blank">bsd.lib.=
mk</a>, <a href=3D"http://bsd.prog.mk" rel=3D"noreferrer" target=3D"_blank"=
>bsd.prog.mk</a>, (and bsd.*.mk, ...).<br></blockquote><div><br></div><div>=
This is what Cy was advocating. We have a dozen or so moved from base</div>=
<div>to ports repos on our freebsd github that have done just that.</div><d=
iv>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0p=
x 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
Then, a separate discussion can be held whether to generate a new<br>
ports entry. This at least gets the components out of base, but usable<br>
for those users who need ;it. Users could clone the repo, cd to it,<br>
and `make install` it).<br></blockquote><div><br></div><div>And also submit=
 pull requests and show that people care enough to carry</div><div>the lpr/=
lpd water.</div><div><br></div><div>I&#39;d lean towards having it as a por=
t because within its security model,</div><div>which is admittedly weak, it=
 works. Heck, we have telnetd as a port</div><div>which also has a problema=
tical security model...</div><div>=C2=A0</div><blockquote class=3D"gmail_qu=
ote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,20=
4);padding-left:1ex">
This would provide a middle-ground, where a piece of software that is<br>
known to be problematic is still useable, but not via normal channels.<br>
Operators would be explicitly opting into lpr.<br></blockquote><div><br></d=
iv><div>Yea, pkg install freebsd-lpr is a strong opt-in statement without b=
eing burdensome.</div><div><br></div><div>Warner</div><div>=C2=A0</div><blo=
ckquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left=
:1px solid rgb(204,204,204);padding-left:1ex">
Thanks,<br>
<br>
-- <br>
Shawn Webb<br>
Cofounder / Security Engineer<br>
HardenedBSD<br>
<br>
Signal Username:=C2=A0 shawn_webb.74<br>
Tor-ified Signal: +1 303-901-1600 / shawn_webb_opsec.50<br>
<a href=3D"https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/raw/master/Sha=
wn_Webb/03A4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc" rel=3D"noreferrer=
" target=3D"_blank">https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/raw/m=
aster/Shawn_Webb/03A4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc</a><br>
</blockquote></div></div>

--0000000000006d7bfb064bc3ead8--