krb5-1.13.2+dfsg-5 source contains source subject to the aladdin license

Bug #1644595 reported by David Simons
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Kerberos
Fix Released
Unknown
krb5 (Ubuntu)
Fix Released
High
Unassigned

Bug Description

The krb5-1.13.2+dfsg-5 package source contains a file autolock.hxx in the directory krb5-1.13.2+dfsg-5\krb5_1.13.2+dfsg.orig\krb5-1.13.2+dfsg\src\ccapi\common\win\OldCC. Although not declared in any other licensing file for this package the file contains comments indicating its subject to the Aladdin license which has implications for any commercial distribution of the software, specifically:

“2(a) Distribution of the Program or any work based on the Program by a commercial organization to any third party is prohibited if any payment is made in connection with such distribution, whether directly (as in payment for a copy fo the Program) or indirectly (as in payment for some service related to the Program, or payment for some product or service that includes a copy of the Program ‘without charge’ . . .”

This file clearly is not needed or used for any Linux build as it appears specific to windows.

Revision history for this message
Christian Ehrhardt  (paelzer) wrote :

Hi,
thank you for your report on this - I must admit I'm not an expert on this.
I checked the actually delivered binaries do not contain any reference - as you outlined this is due to the respective file only being for win support.

In what extend the file being (unused) in the source is a violation I have no idea.
We likely want to drop or mention it in Debian and Ubuntu the same way.
I'll ask more developers how to proceed here.

Thank you!

Changed in krb5 (Ubuntu):
status: New → Confirmed
importance: Undecided → High
Revision history for this message
Robie Basak (racb) wrote :

I cannot find the license claim mentioned. In the source for krb5 1.13.2+dfsg-5, I see src/ccapi/common/win/OldCC/autolock.hxx but it appears to have a regular MIT-style license boilerplate. It has sha256sum 02d63ce54f142101910143464f9eea3935f7d478e4e32998f5ba02cf8ffddc61. I also grepped for Aladdin (case insenstive) and nothing came up. Are you sure you don't have some local filesystem corruption or something like that? Can you confirm with "pull-lp-source" on a different system that you can pull the source file with the license you found, and provide the top line of the debian/changelog file in that source tree?

Marking Incomplete as I cannot find any evidence of a license problem in the source itself.

Changed in krb5 (Ubuntu):
status: Confirmed → Incomplete
Revision history for this message
Robie Basak (racb) wrote :

I'm sorry, my mistake. I see what you mean now. It's "Alladin Free Public License", is mentioned in the boilerplate, but the associated copy of the license doesn't appear to be included.

Changed in krb5 (Ubuntu):
status: Incomplete → Confirmed
Revision history for this message
Christian Ehrhardt  (paelzer) wrote :

Reported to Debian as that is an issue we share, linked the deb-bug here.

Revision history for this message
Sam Hartman (hartmans) wrote : Re: [Bug 1644595] Re: krb5-1.13.2+dfsg-5 source contains source subject to the aladdin license

As a FYI, upstream has relicensed the file under their standard license
with permission from the author.
Coming to Debian soon.

Changed in kerberos:
status: Unknown → Fix Committed
Changed in kerberos:
status: Fix Committed → Fix Released
Revision history for this message
Robie Basak (racb) wrote :

Thanks Sam!

Changed in krb5 (Ubuntu):
status: Confirmed → Triaged
Revision history for this message
Christian Ehrhardt  (paelzer) wrote :

Fixed since 1.15-1, which is quite a while ago.
Clearing this old bug by updating the status.

Changed in krb5 (Ubuntu):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.