#1067946 dietlibc: Includes non-free Sun RPC

#1067946#5
Date:
2024-03-29 10:50:07 UTC
From:
To:
dietlibc includes the sunrpc code from old glibc versions, which is demonstrated to be non-free in #181493.
I have already informed upstream about it. Please replace that code with the current glibc sunrpc, which was relicensed to a BSD license.

Also, please add the license to d/copyright.

#1067946#10
Date:
2024-03-29 21:47:21 UTC
From:
To:
Bastian Germann dixit:

The text in dietlibc reads thusly though:

								  Users
 * may copy or modify Sun RPC without charge, but are not authorized
 * to license or distribute it to anyone else except as part of a product or
 * program developed by the user.

One could argue that dietlibc is a product developed by Fefe,
who then licences and distributes it (under GPL) to others,
which (as long as that notice is included) is covered. I see
dancer already said so, and…

| Sun has repeatedly clarified elsewhere that the intent of this is
| essentially "MIT/X11, except you may not distribute this product
| alone."

… don’t we have other things like that in the archive, with
the justification that it’s trivial to add something to it.

And I don’t follow the others in that thread who think that
the licence of the product developed by the (first) user cannot
be transitive. Note both IANAL+TINLA, but so are the folks on
d-legal. The clarification by Sun also says so.

Not that I’m adverse to replacing things with better-licenced
things, but I don’t think it warrants rc-bugginess (the lack
of the licence in d/copyright does but is a different topic).


But…

… this is where this is best dealt with. Thanks.

bye,
//mirabilos

#1067946#15
Date:
2024-05-04 01:33:46 UTC
From:
To:
Hi Bastian,

did you do that on a mailing list? Do you have a link?
What did upstream say?

Still unconvinced,
//mirabilos

#1067946#20
Date:
2024-05-12 14:23:09 UTC
From:
To:
Am 04.05.24 um 03:33 schrieb Thorsten Glaser:

I have reported to felix-dietlibc@fefe.de.

No. It is not a public address.

No upstream response up to now.

#1067946#25
Date:
2024-05-12 20:25:55 UTC
From:
To:
Bastian Germann dixit:

Ah, yes, that is unfortunate. I used to be subscribed and have no
idea why I’m not, but I re-subscribed (though have not yet seen any
traffic in the last couple of days).

OK.

I just asked in #d-ftp whether we can get an official statement
on whether “we received this as part of dietlibc (a product or
program developed by user” (i.e. Fefe) under GPL will suffice
(which I personally consider true).

If they say yes, I’ll fix that the block is missing from d/copyright
and have a look at #1069365 (unless Christian prefers to).

If they say no, we’ll have to inform reverse dependencies of this,
ask upstream again with some more urgency, and prepare for removal
of this meanwhile (I don’t think we can just swap out such much code
in the packaging)… or possibly excise the sunrpc code and hope this
doesn’t break any users.

Until then… no idea. Wait and drink tea, or something?

bye,
//mirabilos

#1067946#34
Date:
2024-07-04 09:36:36 UTC
From:
To:
severity 1067946 important
thanks

Hi Bastian,

I’m lowering this to nōn-RC severity until we have an ftpmaster
decision either way (I got the understanding that you wanted to
clarify it, not to fight against inclusion).

I’ve given my rationale and it’s ftpmaster, not d-legal (which
is an open mailing list for “armchair lawyers”, i.e. not even
legal experts, to comment, but has no actual bearing), who decide
what ends up in Debian and what not, and this has already passed
ftpmaster review in the past.

This way I can work on the other bugs and we get to keep the
status quo, until there’s a binding decision.

In general interest, I would ask you to use important severity,
not rc, and add as blocking bug #1072165, when you report the
same issue to other packages that are in a similar position (i.e.
parts of sunrpc included as part of a much larger licenced work).

bye,
//mirabilos

#1067946#37
Date:
2024-07-04 09:36:36 UTC
From:
To:
severity 1067946 important
thanks

Hi Bastian,

I’m lowering this to nōn-RC severity until we have an ftpmaster
decision either way (I got the understanding that you wanted to
clarify it, not to fight against inclusion).

I’ve given my rationale and it’s ftpmaster, not d-legal (which
is an open mailing list for “armchair lawyers”, i.e. not even
legal experts, to comment, but has no actual bearing), who decide
what ends up in Debian and what not, and this has already passed
ftpmaster review in the past.

This way I can work on the other bugs and we get to keep the
status quo, until there’s a binding decision.

In general interest, I would ask you to use important severity,
not rc, and add as blocking bug #1072165, when you report the
same issue to other packages that are in a similar position (i.e.
parts of sunrpc included as part of a much larger licenced work).

bye,
//mirabilos