- Package:
- src:dietlibc
- Source:
- src:dietlibc
- Submitter:
- Bastian Germann
- Date:
- 2026-09-11 06:07:01 UTC
- Severity:
- normal
dietlibc includes the sunrpc code from old glibc versions, which is demonstrated to be non-free in #181493. I have already informed upstream about it. Please replace that code with the current glibc sunrpc, which was relicensed to a BSD license. Also, please add the license to d/copyright.
Bastian Germann dixit: The text in dietlibc reads thusly though: Users * may copy or modify Sun RPC without charge, but are not authorized * to license or distribute it to anyone else except as part of a product or * program developed by the user. One could argue that dietlibc is a product developed by Fefe, who then licences and distributes it (under GPL) to others, which (as long as that notice is included) is covered. I see dancer already said so, and… | Sun has repeatedly clarified elsewhere that the intent of this is | essentially "MIT/X11, except you may not distribute this product | alone." … don’t we have other things like that in the archive, with the justification that it’s trivial to add something to it. And I don’t follow the others in that thread who think that the licence of the product developed by the (first) user cannot be transitive. Note both IANAL+TINLA, but so are the folks on d-legal. The clarification by Sun also says so. Not that I’m adverse to replacing things with better-licenced things, but I don’t think it warrants rc-bugginess (the lack of the licence in d/copyright does but is a different topic). But… … this is where this is best dealt with. Thanks. bye, //mirabilos
Hi Bastian, did you do that on a mailing list? Do you have a link? What did upstream say? Still unconvinced, //mirabilos
Am 04.05.24 um 03:33 schrieb Thorsten Glaser: I have reported to felix-dietlibc@fefe.de. No. It is not a public address. No upstream response up to now.
Bastian Germann dixit: Ah, yes, that is unfortunate. I used to be subscribed and have no idea why I’m not, but I re-subscribed (though have not yet seen any traffic in the last couple of days). OK. I just asked in #d-ftp whether we can get an official statement on whether “we received this as part of dietlibc (a product or program developed by user” (i.e. Fefe) under GPL will suffice (which I personally consider true). If they say yes, I’ll fix that the block is missing from d/copyright and have a look at #1069365 (unless Christian prefers to). If they say no, we’ll have to inform reverse dependencies of this, ask upstream again with some more urgency, and prepare for removal of this meanwhile (I don’t think we can just swap out such much code in the packaging)… or possibly excise the sunrpc code and hope this doesn’t break any users. Until then… no idea. Wait and drink tea, or something? bye, //mirabilos
severity 1067946 important thanks Hi Bastian, I’m lowering this to nōn-RC severity until we have an ftpmaster decision either way (I got the understanding that you wanted to clarify it, not to fight against inclusion). I’ve given my rationale and it’s ftpmaster, not d-legal (which is an open mailing list for “armchair lawyers”, i.e. not even legal experts, to comment, but has no actual bearing), who decide what ends up in Debian and what not, and this has already passed ftpmaster review in the past. This way I can work on the other bugs and we get to keep the status quo, until there’s a binding decision. In general interest, I would ask you to use important severity, not rc, and add as blocking bug #1072165, when you report the same issue to other packages that are in a similar position (i.e. parts of sunrpc included as part of a much larger licenced work). bye, //mirabilos
severity 1067946 important thanks Hi Bastian, I’m lowering this to nōn-RC severity until we have an ftpmaster decision either way (I got the understanding that you wanted to clarify it, not to fight against inclusion). I’ve given my rationale and it’s ftpmaster, not d-legal (which is an open mailing list for “armchair lawyers”, i.e. not even legal experts, to comment, but has no actual bearing), who decide what ends up in Debian and what not, and this has already passed ftpmaster review in the past. This way I can work on the other bugs and we get to keep the status quo, until there’s a binding decision. In general interest, I would ask you to use important severity, not rc, and add as blocking bug #1072165, when you report the same issue to other packages that are in a similar position (i.e. parts of sunrpc included as part of a much larger licenced work). bye, //mirabilos
Andrew from the DFSG Team that took over this responsibility from ftpmaster considers the Sun RPC license non-free.
I would like to see what consideration was given to the argument that dietlibc received the files as part of the product dietlibc, under GPL. That is, very specifically, my interpretation is: the licence specifically grants: | […] Users | * may copy or modify Sun RPC without charge, but are not authorized | * to license or distribute it to anyone else except as part of a product or | * program developed by the user. My argument: Debian received this particular copy of Sun RPC as part of dietlibc, under GPL, from Fefe. While the licence requires… | * Sun RPC is a product of Sun Microsystems, Inc. and is provided for | * unrestricted use provided that this legend is included on all tape | * media and as a part of the software program in whole or part. … that this preceise remark be kept, which is not in conflict with the terms of the GPL, dietlibc is actually under GPL so its terms apply, which are DFSG-free enough. That is: while we must retain the notice, the terms that *actually* apply to the modified files is the GPL. ──────────────────────────────────────────────────────────────────────── More practically: the linked posts… • https://web.archive.org/web/20260605022846/https://spot.livejournal.com/315383.html • https://web.archive.org/web/20090328132957/http://blogs.sun.com/webmink/entry/old_code_and_old_licenses … are so sparse in information that it is impractical to impossible for anyone to apply the relicencing findings to any other code. In particular, you’d need to have a tarball with all the relicenced files and the new licence. I looked at OpenSolaris, but that is not helpful here, because it has them under CDDL. (They did mention they used OpenSolaris, but only to figure out the authors.) There’s also merely a saying that they were relicenced, but not the details (scope, new licence, etc). If there is such a tarball (maybe involve both Simon Phipps and “spot” to get one), then we can look at which files match most closely, diff, ask potential coauthors, etc. (if the difference is small enough, we get lucky; otherwise, for dietlibc, the prospect is not well, and in that case, I’d just rip out the entire affected files and break users) bye, //mirabilos
We believe that the bug you reported is fixed in the latest version of dietlibc, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1067946@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Thorsten Glaser <tg@mirbsd.de> (supplier of updated dietlibc package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Fri, 11 Sep 2026 05:35:02 +0000 Source: dietlibc Architecture: source Version: 0.34~cvs20160606+ds-20 Distribution: unstable Urgency: high Maintainer: Christian Seiler <christian@iwakd.de> Changed-By: Thorsten Glaser <tg@mirbsd.de> Closes: 1067946 Changes: dietlibc (0.34~cvs20160606+ds-20) unstable; urgency=high . * remove Sun RPC (Closes: #1067946) * address lintian’s concerns Checksums-Sha1: 36bc8f67065786e42bf4d9a7eed9c2a8d4b8a6b4 2357 dietlibc_0.34~cvs20160606+ds-20.dsc 300f3027068f80f5a857ca51df982064932f5111 566864 dietlibc_0.34~cvs20160606+ds.orig.tar.xz 3fc6b4d2667737b06c92de7a85b278730810b5d1 54924 dietlibc_0.34~cvs20160606+ds-20.debian.tar.xz Checksums-Sha256: 32f8e27fde214da8296f1c62916b027acf8ecad47dccbeaafb365bce61a3c0d5 2357 dietlibc_0.34~cvs20160606+ds-20.dsc 5d8065bbda7e01ee5a08f7c13b4be0e93fd2dcf30b1df2503f6a0258f2ced054 566864 dietlibc_0.34~cvs20160606+ds.orig.tar.xz 3dadf5144fb47c34f9bffca8ecab1ae4ec4b640462d8c44a5309713786092002 54924 dietlibc_0.34~cvs20160606+ds-20.debian.tar.xz Files: 19dbbdfdde77cc6fa8ca9d6a289516a2 2357 devel - dietlibc_0.34~cvs20160606+ds-20.dsc 3b1dfd98c995e192fe130c1a1781cbda 566864 devel - dietlibc_0.34~cvs20160606+ds.orig.tar.xz ac11b360f34c23be56fc64c45a7421a5 54924 devel - dietlibc_0.34~cvs20160606+ds-20.debian.tar.xz iQIcBAEBCQAGBQJqo5RfAAoJEHa1NLLpkAfgE2IP/ikagwJeax0moerZVTXNtTRk xCgj8kVcCCAXwkpXdaDd+62SguamZjTwzx+OphPUyxACMKFSCQQqKiDubzsx0h80 YKCjbs/s7lFg8i3gvXJtmopQseBFN/NIOScIxuTV4+RkEP7DqjrRFtDax5V0UTSV siyHJLRmM2XKsiKN6AqT6mY46YP0zUm5vQ/Qq7N4GF16NWBAtZGwVq0yKEM+PGRc R48xA9oNkw1ZNILKEUzK7pc5xtsuTHK0AOT5Djl6z/BN9yuy8ZPA7P9Xu7UNdKsB IDME2a/zMYbEHJ322aXWSbwr/2aFjIjZsvdrH7hu/AdtlLWfZIObeo96iu+LuZfR cI84ikU/2yJZ1kQddDpOM/mHFwcYEzg1gkZCyKGArNDqVBzSP70p4tXCg6B3A/Hp JjRII5JnpcB+vQZvIpr4BhsrOOtVkJdqqHeFw1sm5GTPKcR1ECeiSkHPd1MQeMeJ 0fXD91QU9kIvx12uIokCWs0q9fxB5MtrDQYp65qXLqZO/jT6x8qXov6c0aJCMHqj C20m9LyzvGk0PG5HRHKRe5+H2rMyH+OTyaPvofDDdV7OQtvEPF+YtA/Cf0OzYruu 1fHdNK2BqhZj/+XArlaNYUrot55/oo8kNClcQK/GGTTeSYIl9+beI8NJyyEje+cn HVpcukf+hPG/BQooPQTY =dC8k -----END PGP SIGNATURE-----