Bug 216774 - sysutils/e2fsprogs: tarball contains code conflicting with its license
Summary: sysutils/e2fsprogs: tarball contains code conflicting with its license
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Some People
Assignee: Matthias Andree
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-02-04 11:43 UTC by Thomas Zander
Modified: 2017-02-06 08:17 UTC (History)
0 users

See Also:
mandree: maintainer-feedback+
mandree: merge-quarterly+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Zander freebsd_committer freebsd_triage 2017-02-04 11:43:24 UTC
From the release notes of the latest upstream release (as of 2017-01-31):
[...]
Replace a test file but which had a "non-commercial use-only" copyright permission file with a newer version from the Cyrus imapd package which now has a 4-clause BSD license, which was making some lawyers nervous, even though the test file in question was only used in lib/et's regression testing and was never included in any compiled binary. (Addresses Debian Bug: #840733)
[...]

Updating to 1.43.4 or later will resolve this.
Comment 1 Matthias Andree freebsd_committer freebsd_triage 2017-02-05 23:40:03 UTC
committed on head/, pending MFH approval to 2017Q1 from ports-secteam@
Comment 2 commit-hook freebsd_committer freebsd_triage 2017-02-05 23:40:17 UTC
A commit references this bug:

Author: mandree
Date: Sun Feb  5 23:39:15 UTC 2017
New revision: 433466
URL: https://svnweb.freebsd.org/changeset/ports/433466

Log:
  Update e2fsprogs to new upstream release 1.43.4.

  This is predominantly a bug-fix release, it however ceases installing
  the *ext4dev files, which have been replaced by *ext4 for quite a while,
  and adds two translations [fi, ms].

  While here, reset PORTREVISION on two slave ports.

  ChangeLog: <http://e2fsprogs.sourceforge.net/e2fsprogs-release.html#1.43.4>

  Note in particular this part of the ChangeLog:
  ?Replace a test file but which had a "non-commercial use-only" copyright
  permission file with a newer version from the Cyrus imapd package which
  now has a 4-clause BSD license, which was making some lawyers nervous,
  even though the test file in question was only used in lib/et's
  regression testing and was never included in any compiled binary.
  (Addresses Debian Bug: #840733)?

  PR:		216774
  Reported by:	Thomas Zander (riggs@)
  MFH:		2017Q1

Changes:
  head/misc/e2fsprogs-libblkid/Makefile
  head/misc/e2fsprogs-libuuid/Makefile
  head/sysutils/e2fsprogs/Makefile
  head/sysutils/e2fsprogs/distinfo
  head/sysutils/e2fsprogs/files/patch-lib_ext2fs_unix__io.c
  head/sysutils/e2fsprogs/pkg-plist
Comment 3 commit-hook freebsd_committer freebsd_triage 2017-02-06 08:15:21 UTC
A commit references this bug:

Author: mandree
Date: Mon Feb  6 08:14:30 UTC 2017
New revision: 433475
URL: https://svnweb.freebsd.org/changeset/ports/433475

Log:
  MFH: r433466

  Update e2fsprogs to new upstream release 1.43.4.

  This is predominantly a bug-fix release, it however ceases installing
  the *ext4dev files, which have been replaced by *ext4 for quite a while,
  and adds two translations [fi, ms].

  While here, reset PORTREVISION on two slave ports.

  ChangeLog: <http://e2fsprogs.sourceforge.net/e2fsprogs-release.html#1.43.4>

  Note in particular this part of the ChangeLog:
  ?Replace a test file but which had a "non-commercial use-only" copyright
  permission file with a newer version from the Cyrus imapd package which
  now has a 4-clause BSD license, which was making some lawyers nervous,
  even though the test file in question was only used in lib/et's
  regression testing and was never included in any compiled binary.
  (Addresses Debian Bug: #840733)?

  PR:		216774
  Reported by:	Thomas Zander (riggs@)

  Approved by:	ports-secteam (junovitch@)

Changes:
_U  branches/2017Q1/
  branches/2017Q1/misc/e2fsprogs-libblkid/Makefile
  branches/2017Q1/misc/e2fsprogs-libuuid/Makefile
  branches/2017Q1/sysutils/e2fsprogs/Makefile
  branches/2017Q1/sysutils/e2fsprogs/distinfo
  branches/2017Q1/sysutils/e2fsprogs/files/patch-lib_ext2fs_unix__io.c
  branches/2017Q1/sysutils/e2fsprogs/pkg-plist
Comment 4 Matthias Andree freebsd_committer freebsd_triage 2017-02-06 08:17:36 UTC
Thomas, thanks for the keen eye, unfortunately the directory structure on sourceforge.net for this project does not lend itself to portscout, I need to see about that.