--- Begin Message ---
- To: Debian Bug Tracking System <submit@bugs.debian.org>
- Subject: kdelibs: inadequate copyright file prevents binary packages from being legally distributable
- From: Mike O'Connor <stew@vireo.org>
- Date: Fri, 20 Mar 2009 03:22:40 -0400
- Message-id: <20090320072240.21994.70027.reportbug@tang.vireo.org>
Package: kdelibs
Version: 4:3.5.10.dfsg.1-2
Severity: serious
Justification: Policy 12.5
Sune suggested I look at kde packages to see if they have adequate
debian/copyright.  I'm sorry but they don't seem to.  Although I only
did a very brief check, I see several problems right away.  Below are
some of the problems I immediately spotted.  I didn't do a full scan
of the source for other license problems, but that clearly needs to be
done.
./kio/kio/ksambashare.cpp:
   This library is free software; you can redistribute it and/or
   modify it under the terms of the GNU Library General Public
   License version 2 as published by the Free Software Foundation.
There are many files like this one that are GPLv2 only.  The copyright
file refers to /usr/share/common-licenses/GPL which is GPL3+
--
kdelibs-3.5.10/kinit/setproctitle* are distributed under a license not
mentioned in debian/copyright. 
--
many files are under a BSD license which explicitly states:
Redistributions in binary form must reproduce the above copyright
but the above copyright isn't duplicated in the binary packages.
oThese copyright statemnts must appear in debian/copyright
---
several files in kdecore/network contain a license not mentioned in
debian/copyright:
 *  Permission is hereby granted, free of charge, to any person obtaining
 *  a copy of this software and associated documentation files (the
 *  "Software"), to deal in the Software without restriction, including
 *  without limitation the rights to use, copy, modify, merge, publish,
 *  distribute, sublicense, and/or sell copies of the Software, and to
 *  permit persons to whom the Software is furnished to do so, subject to
 *  the following conditions:
 *
 *  The above copyright notice and this permission notice shall be included 
 *  in all copies or substantial portions of the Software.
and the copyright holders are not listed as in the binary packages as
is required for distribution.
---
bye,
stew
-- System Information:
Debian Release: 5.0
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'stable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Kernel: Linux 2.6.28-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash
Versions of packages kdelibs depends on:
ii  kdelibs-data        4:3.5.10.dfsg.1-1    core shared data for all KDE appli
ii  kdelibs4c2a         4:3.5.10.dfsg.1-1+b1 core libraries and binaries for al
kdelibs recommends no packages.
kdelibs suggests no packages.
--- End Message ---
--- Begin Message ---
Source: kdelibs
Source-Version: 4:3.5.10.dfsg.1-4
We believe that the bug you reported is fixed in the latest version of
kdelibs, which is due to be installed in the Debian FTP archive:
kdelibs-data_3.5.10.dfsg.1-4_all.deb
  to main/k/kdelibs/kdelibs-data_3.5.10.dfsg.1-4_all.deb
kdelibs-dbg_3.5.10.dfsg.1-4_amd64.deb
  to main/k/kdelibs/kdelibs-dbg_3.5.10.dfsg.1-4_amd64.deb
kdelibs4-dev_3.5.10.dfsg.1-4_amd64.deb
  to main/k/kdelibs/kdelibs4-dev_3.5.10.dfsg.1-4_amd64.deb
kdelibs4-doc_3.5.10.dfsg.1-4_all.deb
  to main/k/kdelibs/kdelibs4-doc_3.5.10.dfsg.1-4_all.deb
kdelibs4c2a_3.5.10.dfsg.1-4_amd64.deb
  to main/k/kdelibs/kdelibs4c2a_3.5.10.dfsg.1-4_amd64.deb
kdelibs_3.5.10.dfsg.1-4.diff.gz
  to main/k/kdelibs/kdelibs_3.5.10.dfsg.1-4.diff.gz
kdelibs_3.5.10.dfsg.1-4.dsc
  to main/k/kdelibs/kdelibs_3.5.10.dfsg.1-4.dsc
kdelibs_3.5.10.dfsg.1-4_all.deb
  to main/k/kdelibs/kdelibs_3.5.10.dfsg.1-4_all.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 520485@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org> (supplier of updated kdelibs package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Tue, 03 Aug 2010 19:51:40 -0400
Source: kdelibs
Binary: kdelibs kdelibs-data kdelibs4c2a kdelibs4-dev kdelibs4-doc kdelibs-dbg
Architecture: source all amd64
Version: 4:3.5.10.dfsg.1-4
Distribution: unstable
Urgency: low
Maintainer: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
Changed-By: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
Description: 
 kdelibs    - core libraries from the official KDE release
 kdelibs-data - core shared data for all KDE applications
 kdelibs-dbg - debugging symbols for kdelibs
 kdelibs4-dev - development files for the KDE core libraries
 kdelibs4-doc - developer documentation for the KDE core libraries
 kdelibs4c2a - core libraries and binaries for all KDE applications
Closes: 520485 520977 565013
Changes: 
 kdelibs (4:3.5.10.dfsg.1-4) unstable; urgency=low
 .
   [ Pino Toscano ]
   * Pull upstream r1074155 to fix build with GCC 4.5. (Closes: #565013)
 .
   [ Modestas Vainius ]
   * Do not ship all_languages in kdelibs-data.
 .
   [ Moritz Muehlenhoff ]
   * Update copyright file. (Closes: #520485)
   * License for certbundle files has been clarified. (Closes: #520977)
   * Document scope of security support in Squeeze.
 .
   [ Ana Beatriz Guerrero Lopez ]
   * Update to Standards-Version 3.9.1, no changes required.
   * Add missing ${misc:Depends}.
Checksums-Sha1: 
 d7af0f334afc4184408bea2a041e9223d79c1c34 2178 kdelibs_3.5.10.dfsg.1-4.dsc
 69ef7c977453505cb66c0ee73e13c855fb8b0eca 691768 kdelibs_3.5.10.dfsg.1-4.diff.gz
 eb79e2edea4cfa291739717ff724e399c7cdc122 40694 kdelibs_3.5.10.dfsg.1-4_all.deb
 081d5cdf0c0e1476b5b9dd9b437ffdd48cc0328d 8649680 kdelibs-data_3.5.10.dfsg.1-4_all.deb
 d56ed1e5f499ec1854772c539428be55ec7c69bd 26546076 kdelibs4-doc_3.5.10.dfsg.1-4_all.deb
 dbde574d64b9cd51ce72fe8baf0988dd07a9b44e 11144574 kdelibs4c2a_3.5.10.dfsg.1-4_amd64.deb
 c632e4407273f140bc69387637dc1d65e3945e7f 1460192 kdelibs4-dev_3.5.10.dfsg.1-4_amd64.deb
 3d4190e63217f90578e923038c51a2ca51e0f09d 27418244 kdelibs-dbg_3.5.10.dfsg.1-4_amd64.deb
Checksums-Sha256: 
 540b81decb13b8f87d5be70a1d0c3923ad36ff26db2e003576a96bd49273dd5c 2178 kdelibs_3.5.10.dfsg.1-4.dsc
 2c1fe2948726db5f800bef3a591fa87b7d32ad136c1f9f7c400c9829cb503297 691768 kdelibs_3.5.10.dfsg.1-4.diff.gz
 3394978a7ca22dd5612a4d3eea44903727ea5a9a295b3274859458fd6f2d18da 40694 kdelibs_3.5.10.dfsg.1-4_all.deb
 6dd5b7d68ab4d2572e7b94cb8a2249c15a769998f67873b4493c84d01efd5a24 8649680 kdelibs-data_3.5.10.dfsg.1-4_all.deb
 d747affa7ea16e2a6e8fd5b6a6d271ad420e7809e8f8eae4491ad6e963762c17 26546076 kdelibs4-doc_3.5.10.dfsg.1-4_all.deb
 cceb7a16e3fd24e2daa07feef7e0cca97fb6da8d5da3880ea1a3f5d0dd217b72 11144574 kdelibs4c2a_3.5.10.dfsg.1-4_amd64.deb
 5e0bf8ac5f282bde7abd6b26f73e50f40c7f2585cbd1f397992f13361fe915b2 1460192 kdelibs4-dev_3.5.10.dfsg.1-4_amd64.deb
 2bd94260b823d7fe6b1a396b5cc15ce062f3fde7f267da16e00b29210d4c45c8 27418244 kdelibs-dbg_3.5.10.dfsg.1-4_amd64.deb
Files: 
 4f992628e4eb63468db3de77275a3e04 2178 libs optional kdelibs_3.5.10.dfsg.1-4.dsc
 f509a296aa3a969d52ba645fa2a75c59 691768 libs optional kdelibs_3.5.10.dfsg.1-4.diff.gz
 9cca3251e095ae8f78d6e6100ef7982d 40694 libs optional kdelibs_3.5.10.dfsg.1-4_all.deb
 6c4390c749182450a5aae8d3c6674a45 8649680 libs optional kdelibs-data_3.5.10.dfsg.1-4_all.deb
 3e98835946e2b8bffd0a8a2d2c9ee4e1 26546076 doc optional kdelibs4-doc_3.5.10.dfsg.1-4_all.deb
 9137d69f7dfae1be0bd9e3f3097d8a3d 11144574 libs optional kdelibs4c2a_3.5.10.dfsg.1-4_amd64.deb
 972b108363a536d42b605e72088a2367 1460192 libdevel optional kdelibs4-dev_3.5.10.dfsg.1-4_amd64.deb
 844c2ca0c60cba83b1f1e449eb6b0dc8 27418244 debug extra kdelibs-dbg_3.5.10.dfsg.1-4_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Signed by Ana Guerrero
iEYEARECAAYFAkxYr8AACgkQn3j4POjENGE3hwCffUbydzUfAmdI/QKv2+OQXVjW
RiMAn0xXKI8TBW9LsLg4PNxV8NrJSGNU
=vwap
-----END PGP SIGNATURE-----
--- End Message ---