git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Is getpass(3) really obsolete?

From
TRTheo de Raadt <deraadt@openbsd.org>
Date
Oct 29, 2021, 13:55 UTC
Message-ID
<63238.1635515736@cvs.openbsd.org>
In-Reply-To
<00d501d7ccbe$0169c340$043d49c0$@nexbridge.com>
<rsbecker@nexbridge.com> wrote:
Show 30 quoted lines
> On October 29, 2021 7:29 AM, Alejandro Colomar wrote:
> > On 10/29/21 13:15, Alejandro Colomar wrote:
> > > Hi,
> > >
> > > As the manual pages says, SUSv2 marked it as LEGACY, and POSIX doesn't
> > > have it at all.  The manual page goes further and says "This function
> > > is obsolete. Do not use it." in its first lines.
> > >
> > > But, glibc doesn't seem to have deprecated this function at all.  And
> > > it seems to be the most portable way to get a password, even if it's
> > > not in POSIX.
> > >
> > > BSDs have readpassphrase(3), but glibc doesn't, so unless you
> > > recommend
> > 
> > OpenBSD also marks getpass(3) as obsolete and recommends
> > readpassphrase(3):
> > <https://man.openbsd.org/getpass>
> > 
> > > using readpassphrase(3) from libbsd, or plan to add it to glibc, I
> > > think
> > > getpass(3) should be the recommended function in Linux, and therefore
> > > we should remove the hard words against it.
> > >
> > > As a real example, git(1) uses getpass(3).
> > > <https://github.com/git/git/blob/master/compat/terminal.c>
> > >
> > > What are your thoughts?
> 
> getpass() is obsolete in POSIX.2. However, some platforms still are on POSIX.1, so replacing it instead of providing a configure detection/switch for it might cause issues.
The community finally had the balls to get rid of gets(3).

getpass(3) shares the same flaw, that the buffer size isn't passed. This has been an issue in the past, and incorrectly led to readpassphrase(3)

readpassphrase(3) has a few too many features/extensions for my taste, but at least it is harder to abuse.

Previous: Eugene SyromyatnikovNext: rsbecker@nexbridge.com
Message 9 of 20 in “Re: Is getpass(3) really obsolete?”
  1. Alejandro Colomar (man-pages)Oct 29, 2021
  2. Ævar Arnfjörð BjarmasonOct 29, 2021
  3. Alejandro Colomar (man-pages)Oct 29, 2021
  4. Joseph MyersOct 29, 2021
  5. Alejandro Colomar (man-pages)Oct 30, 2021
  6. Joseph MyersNov 1, 2021
  7. rsbecker@nexbridge.comOct 29, 2021
  8. Eugene SyromyatnikovOct 29, 2021
  9. Theo de RaadtOct 29, 2021
  10. rsbecker@nexbridge.comOct 29, 2021
  11. Theo de RaadtOct 29, 2021
  12. rsbecker@nexbridge.comOct 29, 2021
  13. Alejandro Colomar (man-pages)Oct 29, 2021
  14. rsbecker@nexbridge.comOct 29, 2021
  15. Zack WeinbergOct 29, 2021
  16. readpassphrase(3) in glibc, and agetpass() (Was: Is getpass(3) really obsolete?)Alejandro Colomar, Sep 27, 2022
  17. Alex ColomarSep 27, 2022
  18. Sam JamesSep 27, 2022
  19. getpass.3: SYNOPSIS: Mark getpass() as [[deprecated]]Alejandro Colomar, Oct 29, 2021
  20. Jeff KingOct 29, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.