Package: pcp
Version: 6.3.8-1
Severity: normal
Dear Maintainer,
I installed dstat on a new Debian 13.3 server and later noticed that it
had actually installed the virtual package pcp (no problem), which
listens on all interfaces by default:
```
tcp 0 0 0.0.0.0:44321 0.0.0.0:* LISTEN
4920/pmcd
tcp 0 0 0.0.0.0:4330 0.0.0.0:* LISTEN
5251/pmlogger
tcp6 0 0 :::44321 :::* LISTEN
4920/pmcd
tcp6 0 0 :::4330 :::* LISTEN
5251/pmlogger
```
This was an unexpected change from Debian 12, where dstat installed
dstat - again, my bad - which does not listen on any public interfaces.
I am not sure if pcp needs to listen on all interfaces, or if it could
just listen on loopback. I think that would be a preferable default.
-- System Information:
Debian Release: 13.3
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500,
'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 6.12.73+deb13-amd64 (SMP w/56 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE,
TAINT_UNSIGNED_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE
not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages pcp depends on:
ii gawk 1:5.2.1-2+b1
ii libbpf1 1:1.5.0-3
ii libc6 2.41-12+deb13u1
ii libelf1t64 0.192-4
ii libncursesw6 6.5+20250216-2
ii libpcp-archive1 6.3.8-1
ii libpcp-gui2 6.3.8-1
ii libpcp-import1 6.3.8-1
ii libpcp-mmv1 6.3.8-1
ii libpcp-pmda3 6.3.8-1
ii libpcp-trace2 6.3.8-1
ii libpcp-web1 6.3.8-1
ii libpcp3 6.3.8-1
ii libpfm4 4.13.0+git99-gc5587f9-1
ii libreadline8t64 8.2-6
ii libssl3t64 3.5.4-1~deb13u2
ii libtinfo6 6.5+20250216-2
ii libuv1t64 1.50.0-2
ii pcp-conf 6.3.8-1
ii procps 2:4.0.4-9
ii python3 3.13.5-1
ii python3-pcp 6.3.8-1
ii zlib1g 1:1.3.dfsg+really1.3.1-1+b1
Versions of packages pcp recommends:
ii libpcp-pmda-perl 6.3.8-1
Versions of packages pcp suggests:
pn bpftrace <none>
pn libpcp-import-perl <none>
pn pcp-gui <none>
pn python3-bpfcc <none>
pn redis-server <none>
ii zstd 1.5.7+dfsg-1
-- no debconf information