Re: Retiring lpr and lpd
Warner Losh <[email protected]> Thu, 26 Feb 2026 18:11:12 -0700
| Newsgroups | gmane.os.freebsd.architechture |
|---|---|
| Message-ID | <CANCZdfovc3pfj8_q8UqkcdckjNnKEU-NWfQMV=xpBX8d8L7Arg@mail.gmail.com> |
--0000000000006d7bfb064bc3ead8 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Thu, Feb 26, 2026 at 1:22=E2=80=AFPM Shawn Webb <shawn.webb@hardenedbsd.= org> wrote: > With that said, a random idea poppped in my head. I'm not advocating > for the idea, I'm simply hoping to convey the idea. > > What if the lpr/lpd (and related?) components (I'm just gonna say lpr > from now on to be brief, but please understand I mean any/all > components involved) are separated out to a wholly separate git repo > (specific to lpr). > > This repo would be self-contained and buildable as an out-of-tree > component. So you'd have your BSD-flavor Makefiles that use the normal > bsd.lib.mk, bsd.prog.mk, (and bsd.*.mk, ...). > This is what Cy was advocating. We have a dozen or so moved from base to ports repos on our freebsd github that have done just that. > Then, a separate discussion can be held whether to generate a new > ports entry. This at least gets the components out of base, but usable > for those users who need ;it. Users could clone the repo, cd to it, > and `make install` it). > And also submit pull requests and show that people care enough to carry the lpr/lpd water. I'd lean towards having it as a port because within its security model, which is admittedly weak, it works. Heck, we have telnetd as a port which also has a problematical security model... > This would provide a middle-ground, where a piece of software that is > known to be problematic is still useable, but not via normal channels. > Operators would be explicitly opting into lpr. > Yea, pkg install freebsd-lpr is a strong opt-in statement without being burdensome. Warner > Thanks, > > -- > Shawn Webb > Cofounder / Security Engineer > HardenedBSD > > Signal Username: shawn_webb.74 > Tor-ified Signal: +1 303-901-1600 / shawn_webb_opsec.50 > > https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/raw/master/Shawn_Webb/0= 3A4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc > --0000000000006d7bfb064bc3ead8 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g= mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, Feb 26,= 2026 at 1:22=E2=80=AFPM Shawn Webb <<a href=3D"mailto:shawn.webb@harden= edbsd.org">[email protected]</a>> wrote:<br></div><blockquote c= lass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px soli= d rgb(204,204,204);padding-left:1ex">With that said, a random idea poppped = in my head. I'm not advocating<br> for the idea, I'm simply hoping to convey the idea.<br> <br> What if the lpr/lpd (and related?) components (I'm just gonna say lpr<b= r> from now on to be brief, but please understand I mean any/all<br> components involved) are separated out to a wholly separate git repo<br> (specific to lpr).<br> <br> This repo would be self-contained and buildable as an out-of-tree<br> component. So you'd have your BSD-flavor Makefiles that use the normal<= br> <a href=3D"http://bsd.lib.mk" rel=3D"noreferrer" target=3D"_blank">bsd.lib.= mk</a>, <a href=3D"http://bsd.prog.mk" rel=3D"noreferrer" target=3D"_blank"= >bsd.prog.mk</a>, (and bsd.*.mk, ...).<br></blockquote><div><br></div><div>= This is what Cy was advocating. We have a dozen or so moved from base</div>= <div>to ports repos on our freebsd github that have done just that.</div><d= iv>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0p= x 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> Then, a separate discussion can be held whether to generate a new<br> ports entry. This at least gets the components out of base, but usable<br> for those users who need ;it. Users could clone the repo, cd to it,<br> and `make install` it).<br></blockquote><div><br></div><div>And also submit= pull requests and show that people care enough to carry</div><div>the lpr/= lpd water.</div><div><br></div><div>I'd lean towards having it as a por= t because within its security model,</div><div>which is admittedly weak, it= works. Heck, we have telnetd as a port</div><div>which also has a problema= tical security model...</div><div>=C2=A0</div><blockquote class=3D"gmail_qu= ote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,20= 4);padding-left:1ex"> This would provide a middle-ground, where a piece of software that is<br> known to be problematic is still useable, but not via normal channels.<br> Operators would be explicitly opting into lpr.<br></blockquote><div><br></d= iv><div>Yea, pkg install freebsd-lpr is a strong opt-in statement without b= eing burdensome.</div><div><br></div><div>Warner</div><div>=C2=A0</div><blo= ckquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left= :1px solid rgb(204,204,204);padding-left:1ex"> Thanks,<br> <br> -- <br> Shawn Webb<br> Cofounder / Security Engineer<br> HardenedBSD<br> <br> Signal Username:=C2=A0 shawn_webb.74<br> Tor-ified Signal: +1 303-901-1600 / shawn_webb_opsec.50<br> <a href=3D"https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/raw/master/Sha= wn_Webb/03A4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc" rel=3D"noreferrer= " target=3D"_blank">https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/raw/m= aster/Shawn_Webb/03A4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc</a><br> </blockquote></div></div> --0000000000006d7bfb064bc3ead8--