git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Is getpass(3) really obsolete?

From
AMAlejandro Colomar (man-pages) <alx.manpages@gmail.com>
Date
Oct 29, 2021, 14:44 UTC
Message-ID
<326e75f9-f732-a7a8-22dc-5fc304601b39@gmail.com>
In-Reply-To
<00e701d7ccd2$058b9070$10a2b150$@nexbridge.com>
Hi Randall, Theo,
On 10/29/21 16:33, rsbecker@nexbridge.com wrote:
Show 17 quoted lines
> October 29, 2031 10:21 AM, Theo de Raadt will write:
>> <rsbecker@nexbridge.com> wrote:
>>
>>>>> getpass() is obsolete in POSIX.2. However, some platforms still
>>>>> are on
>>> POSIX.1,
>>>> so replacing it instead of providing a configure detection/switch
>>>> for it
>>> might
>>>> cause issues.
>>>>
>>>>
>>>> The community finally had the balls to get rid of gets(3).
>>>>
>>>> getpass(3) shares the same flaw, that the buffer size isn't passed.
>>>> This has been an issue in the past, and incorrectly led to
>>> readpassphrase(3)

That seems a good reason to keep the "Do not use it." note in the manual page. I think I'll add a recommendation for readpassphrase(3bsd) for the moment which is the only alternative available in Linux.

Show 8 quoted lines
>>>>
>>>> readpassphrase(3) has a few too many features/extensions for my
>>>> taste, but
>>> at
>>>> least it is harder to abuse.
>>>
>>> readpassphrase is not generally supported. This will break builds on
>>> many platforms.

I found readpassphrase(3) in FreeBSD and OpenBSD. It is also present in libbsd(7), which is available in most Linux distributions. I also found it on a Mac that I have access.

NetBSD has getpass_r(3) instead. It is not in any other system I have access.

Show 7 quoted lines
>>
>> Of course moving forward takes a long time.  If a better API is supplied then
>> there is a choice in 10 years.  If a better API is not supplied, then 10 years from
>> now this conversation can get a reply.
> 
> I checked the API 10 years from now (check the above date) at it's still not there 😉 In the meantime, compatibility is important. I checked the latest release (last week's) on my platform and readpassphrase() is not available. Let's please put a compatibility layer in.
> 

libbsd(7) is probably the compatibility layer that you're looking for. What system are you on?

<https://libbsd.freedesktop.org/wiki/>
Cheers,
Alex
-- 
Alejandro Colomar
Linux man-pages comaintainer; https://www.kernel.org/doc/man-pages/
http://www.alejandro-colomar.es/
Previous: rsbecker@nexbridge.comNext: rsbecker@nexbridge.com
Message 13 of 20 in “Re: Is getpass(3) really obsolete?”
  1. Alejandro Colomar (man-pages)Oct 29, 2021
  2. Ævar Arnfjörð BjarmasonOct 29, 2021
  3. Alejandro Colomar (man-pages)Oct 29, 2021
  4. Joseph MyersOct 29, 2021
  5. Alejandro Colomar (man-pages)Oct 30, 2021
  6. Joseph MyersNov 1, 2021
  7. rsbecker@nexbridge.comOct 29, 2021
  8. Eugene SyromyatnikovOct 29, 2021
  9. Theo de RaadtOct 29, 2021
  10. rsbecker@nexbridge.comOct 29, 2021
  11. Theo de RaadtOct 29, 2021
  12. rsbecker@nexbridge.comOct 29, 2021
  13. Alejandro Colomar (man-pages)Oct 29, 2021
  14. rsbecker@nexbridge.comOct 29, 2021
  15. Zack WeinbergOct 29, 2021
  16. readpassphrase(3) in glibc, and agetpass() (Was: Is getpass(3) really obsolete?)Alejandro Colomar, Sep 27, 2022
  17. Alex ColomarSep 27, 2022
  18. Sam JamesSep 27, 2022
  19. getpass.3: SYNOPSIS: Mark getpass() as [[deprecated]]Alejandro Colomar, Oct 29, 2021
  20. Jeff KingOct 29, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.