- Package:
- src:dietlibc
- Source:
- src:dietlibc
- Submitter:
- Bastian Germann
- Date:
- 2024-07-04 09:42:10 UTC
- Severity:
- normal
dietlibc includes the sunrpc code from old glibc versions, which is demonstrated to be non-free in #181493. I have already informed upstream about it. Please replace that code with the current glibc sunrpc, which was relicensed to a BSD license. Also, please add the license to d/copyright.
Bastian Germann dixit: The text in dietlibc reads thusly though: Users * may copy or modify Sun RPC without charge, but are not authorized * to license or distribute it to anyone else except as part of a product or * program developed by the user. One could argue that dietlibc is a product developed by Fefe, who then licences and distributes it (under GPL) to others, which (as long as that notice is included) is covered. I see dancer already said so, and… | Sun has repeatedly clarified elsewhere that the intent of this is | essentially "MIT/X11, except you may not distribute this product | alone." … don’t we have other things like that in the archive, with the justification that it’s trivial to add something to it. And I don’t follow the others in that thread who think that the licence of the product developed by the (first) user cannot be transitive. Note both IANAL+TINLA, but so are the folks on d-legal. The clarification by Sun also says so. Not that I’m adverse to replacing things with better-licenced things, but I don’t think it warrants rc-bugginess (the lack of the licence in d/copyright does but is a different topic). But… … this is where this is best dealt with. Thanks. bye, //mirabilos
Hi Bastian, did you do that on a mailing list? Do you have a link? What did upstream say? Still unconvinced, //mirabilos
Am 04.05.24 um 03:33 schrieb Thorsten Glaser: I have reported to felix-dietlibc@fefe.de. No. It is not a public address. No upstream response up to now.
Bastian Germann dixit: Ah, yes, that is unfortunate. I used to be subscribed and have no idea why I’m not, but I re-subscribed (though have not yet seen any traffic in the last couple of days). OK. I just asked in #d-ftp whether we can get an official statement on whether “we received this as part of dietlibc (a product or program developed by user” (i.e. Fefe) under GPL will suffice (which I personally consider true). If they say yes, I’ll fix that the block is missing from d/copyright and have a look at #1069365 (unless Christian prefers to). If they say no, we’ll have to inform reverse dependencies of this, ask upstream again with some more urgency, and prepare for removal of this meanwhile (I don’t think we can just swap out such much code in the packaging)… or possibly excise the sunrpc code and hope this doesn’t break any users. Until then… no idea. Wait and drink tea, or something? bye, //mirabilos
severity 1067946 important thanks Hi Bastian, I’m lowering this to nōn-RC severity until we have an ftpmaster decision either way (I got the understanding that you wanted to clarify it, not to fight against inclusion). I’ve given my rationale and it’s ftpmaster, not d-legal (which is an open mailing list for “armchair lawyers”, i.e. not even legal experts, to comment, but has no actual bearing), who decide what ends up in Debian and what not, and this has already passed ftpmaster review in the past. This way I can work on the other bugs and we get to keep the status quo, until there’s a binding decision. In general interest, I would ask you to use important severity, not rc, and add as blocking bug #1072165, when you report the same issue to other packages that are in a similar position (i.e. parts of sunrpc included as part of a much larger licenced work). bye, //mirabilos
severity 1067946 important thanks Hi Bastian, I’m lowering this to nōn-RC severity until we have an ftpmaster decision either way (I got the understanding that you wanted to clarify it, not to fight against inclusion). I’ve given my rationale and it’s ftpmaster, not d-legal (which is an open mailing list for “armchair lawyers”, i.e. not even legal experts, to comment, but has no actual bearing), who decide what ends up in Debian and what not, and this has already passed ftpmaster review in the past. This way I can work on the other bugs and we get to keep the status quo, until there’s a binding decision. In general interest, I would ask you to use important severity, not rc, and add as blocking bug #1072165, when you report the same issue to other packages that are in a similar position (i.e. parts of sunrpc included as part of a much larger licenced work). bye, //mirabilos