Bug 14524 - cairo licensing wrong
Summary: cairo licensing wrong
Status: RESOLVED FIXED
Alias: None
Product: Meta-yocto
Classification: Build System, Metadata & Runtime
Component: meta-yocto (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium normal
Target Milestone: 4.1
Assignee: Richard Purdie
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2021-08-24 11:37 UTC by Frans Meulenbroeks
Modified: 2022-05-09 11:21 UTC (History)
6 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Frans Meulenbroeks 2021-08-24 11:37:44 UTC
I feel the licensing info for cairo is incorrect/incomplete.

The recipe for 1.16 (the one I got with dunfell) reads:

LICENSE = "(MPL-1.1 | LGPLv2.1) & GPLv3+"
LICENSE_${PN} = "MPL-1.1 | LGPLv2.1"
LICENSE_${PN}-dev = "MPL-1.1 | LGPLv2.1"
LICENSE_${PN}-doc = "MPL-1.1 | LGPLv2.1"
LICENSE_${PN}-gobject = "MPL-1.1 | LGPLv2.1"
LICENSE_${PN}-script-interpreter = "MPL-1.1 | LGPLv2.1"
LICENSE_${PN}-perf-utils = "GPLv3+"

If I build with gplv3 disabled I get

WARNING: cairo-1.16.0-r0 do_package: QA Issue: Excluding cairo-src from packaging as it has incompatible license(s): GPL-3.0+ [incompatible-license]
WARNING: cairo-1.16.0-r0 do_package: QA Issue: Excluding cairo-dbg from packaging as it has incompatible license(s): GPL-3.0+ [incompatible-license]
WARNING: cairo-1.16.0-r0 do_package: QA Issue: Excluding cairo-perf-utils from packaging as it has incompatible license(s): GPL-3.0+ [incompatible-license]
WARNING: cairo-1.16.0-r0 do_package: QA Issue: Excluding cairo-staticdev from packaging as it has incompatible license(s): GPL-3.0+ [incompatible-license]
WARNING: cairo-1.16.0-r0 do_package: QA Issue: Excluding cairo-locale from packaging as it has incompatible license(s): GPL-3.0+ [incompatible-license]

However if I look at https://www.cairographics.org/ it reads

Cairo is free software and is available to be redistributed and/or modified under the terms of either the GNU Lesser General Public License (LGPL) version 2.1 or the Mozilla Public License (MPL) version 1.1 at your option.

So I would expect at least cairo-src (and probably also cairo-dbg and cairo-locale) not to be under GPL3
Comment 1 Frans Meulenbroeks 2021-08-24 11:45:49 UTC
btw the same seems to apply to libgcrypt:
https://gnupg.org/software/libgcrypt/index.html says GPLv2+ so I'd say at least the  src, doc and locale packages should be GPLV2+
Comment 2 Joshua Watt 2021-08-26 14:55:35 UTC
The licensing on most of these is probably correct:

 * cairo-src - includes the source for perf-utils, so it does have GPLv3 code
 * cairo-dbg - includes the debug symbols for perf-utils, so it also has GPLv3 code
 * cairo-perf-utils - is GPLv3
 * cairo-staticdev - It's really hard to tell whats in here, but it may or may not have GPLv3 code, and it's probably better to play it safe and say GPLv3.
 * cairo-locale - This one may not actually include any GPLv3, unless it's including locales from perf-utils; someone would need to verify
Comment 3 Frans Meulenbroeks 2021-08-27 09:24:47 UTC
I do not have a non-gplv3 build available at this moment to check if the locale contains any v3 code.

Wrt staticdev: as the dev package is LGPLv2.1 I kind-a expected this one to be the  same. The GPLv3 part is only for perf-utils which are binaries

wrt the -dbg package: ideally each binary package should be accomplished by a dbg package for that package. 

Wrt -src: 
I have no idea what the policy is here: LGPL 2.1 requires to provide source on request. I don't really need the source packages myself.
It would be nice to have src packages for each binary package in a recipe.

Thinking of it, it might be feasible and better to split the recipe in two, one for the lib part and one for the binary part (the perf-utils)
Comment 4 Frans Meulenbroeks 2021-10-18 18:18:33 UTC
I feel this is still an issue.

The sole reason parts of this are GPLv3 is because of the util/cairo-trace folder

It can be considered to create a separate package (maybe in meta-gplv2) that builds and packages cairo without this dir.

I'm not sure if it is possible to have GPL related conditionals in a recipe otherwise it might be possible to replace util/cairo-trace with a dummy or so after unpacking.

Comment1 of this issue also mentions libgcrypt.
All files in libgcrypt, including the COPYING files indicate it is GPLv2 or LGPLv2.1.
The only references to v3 that I could find are in ./build-aux/config.guess and ./build-aux/config.sub

I'm not a copyright person but it seems to me that the intention is definitely to use GPLv2.

Also it seems quite odd for both cairo and libcrypt that we deliver binaries or libs as GPLv2 or LGPLv2.1 but the src is v3. 
That is: I am not sure if it is possible to have a v2 lib derived from sources that are v3
Comment 5 Oleksiy Obitotskyy 2022-02-19 20:21:02 UTC
https://autobuilder.yoctoproject.org/typhoon/#/builders/97/builds/4087/steps/15/logs/stdio

qemuarm64-armhost ubuntu1804-arm-1

WARNING: core-image-sato-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-2.1-only was not in the licenses collected for recipe cairo [license-file-missing]
WARNING: core-image-sato-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-2.1-only was not in the licenses collected for recipe cairo [license-file-missing]
WARNING: core-image-sato-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-3.0-or-later was not in the licenses collected for recipe libksba [license-file-missing]
...
WARNING: core-image-sato-sdk-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-2.1-only was not in the licenses collected for recipe cairo [license-file-missing]
WARNING: core-image-sato-sdk-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-3.0-or-later was not in the licenses collected for recipe libksba [license-file-missing]
Comment 6 Oleksiy Obitotskyy 2022-02-20 16:49:44 UTC
https://autobuilder.yoctoproject.org/typhoon/#/builders/61/builds/4737/steps/11/logs/stdio

pkgman-rpm-non-rpm ubuntu2004-ty-1 

WARNING: cairo-1.16.0-r0 do_package_qa: QA Issue: LICENSE:cairo-doc includes licenses (LGPL-2.1-only) that are not listed in LICENSE [unlisted-pkg-lics]
WARNING: cairo-1.16.0-r0 do_package_qa: QA Issue: LICENSE:cairo-gobject includes licenses (LGPL-2.1-only) that are not listed in LICENSE [unlisted-pkg-lics]
WARNING: cairo-1.16.0-r0 do_package_qa: QA Issue: LICENSE:cairo-dev includes licenses (LGPL-2.1-only) that are not listed in LICENSE [unlisted-pkg-lics]
WARNING: cairo-1.16.0-r0 do_package_qa: QA Issue: LICENSE:cairo-script-interpreter includes licenses (LGPL-2.1-only) that are not listed in LICENSE [unlisted-pkg-lics]
WARNING: cairo-1.16.0-r0 do_package_qa: QA Issue: LICENSE:cairo includes licenses (LGPL-2.1-only) that are not listed in LICENSE [unlisted-pkg-lics]
Comment 7 Oleksiy Obitotskyy 2022-02-20 16:51:23 UTC
Added bug for libksba package https://bugzilla.yoctoproject.org/show_bug.cgi?id=14727 it could be caused by the same reasons and joined with this bug.
Comment 8 Oleksiy Obitotskyy 2022-02-21 07:33:26 UTC
https://autobuilder.yoctoproject.org/typhoon/#/builders/62/builds/4757/steps/11/logs/warnings

edgerouter opensuse153-ty-1 + lot more from the same run


stdio: WARNING: cairo-1.16.0-r0 do_package_qa: QA Issue: LICENSE:cairo-dev includes licenses (LGPL-2.1-only) that are not listed in LICENSE [unlisted-pkg-lics]
stdio: WARNING: cairo-1.16.0-r0 do_package_qa: QA Issue: LICENSE:cairo-gobject includes licenses (LGPL-2.1-only) that are not listed in LICENSE [unlisted-pkg-lics]
stdio: WARNING: cairo-1.16.0-r0 do_package_qa: QA Issue: LICENSE:cairo-doc includes licenses (LGPL-2.1-only) that are not listed in LICENSE [unlisted-pkg-lics]
stdio: WARNING: cairo-1.16.0-r0 do_package_qa: QA Issue: LICENSE:cairo includes licenses (LGPL-2.1-only) that are not listed in LICENSE [unlisted-pkg-lics]
stdio: WARNING: cairo-1.16.0-r0 do_package_qa: QA Issue: LICENSE:cairo-script-interpreter includes licenses (LGPL-2.1-only) that are not listed in LICENSE [unlisted-pkg-lics]
stdio: WARNING: libksba-1.6.0-r0 do_package_qa: QA Issue: LICENSE:libksba includes licenses (LGPL-3.0-or-later) that are not listed in LICENSE [unlisted-pkg-lics]
stdio: WARNING: core-image-sato-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-2.1-only was not in the licenses collected for recipe cairo [license-file-missing]
stdio: WARNING: core-image-sato-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-2.1-only was not in the licenses collected for recipe cairo [license-file-missing]
stdio: WARNING: core-image-sato-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-3.0-or-later was not in the licenses collected for recipe libksba [license-file-missing]
stdio: WARNING: core-image-sato-sdk-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-2.1-only was not in the licenses collected for recipe cairo [license-file-missing]
stdio: WARNING: core-image-sato-sdk-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-2.1-only was not in the licenses collected for recipe cairo [license-file-missing]
stdio: WARNING: core-image-sato-sdk-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-2.1-only was not in the licenses collected for recipe cairo [license-file-missing]
stdio: WARNING: core-image-sato-sdk-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-2.1-only was not in the licenses collected for recipe cairo [license-file-missing]
stdio: WARNING: core-image-sato-sdk-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-3.0-or-later was not in the licenses collected for recipe libksba [license-file-missing]
stdio: WARNING: core-image-ptest-all-1.0-r0 do_rootfs: QA Issue: The license listed LGPL-2.1-only was not in the licenses collected for recipe cairo [license-file-missing]
Comment 9 Richard Purdie 2022-05-05 15:47:56 UTC
The easiest thing to do is pass --disable-trace to cairo configure and then the GPLv3 isn't included.
Comment 10 Richard Purdie 2022-05-05 19:43:30 UTC
I've sent out a patch to clarify the license on cairo. We could make the PACKAGECONFIG remove the GPLv3 license if the trace option is disabled but someone needs to write that patch.

libgcrypt was fixed upstream but the metadata wasn't updated. I've sent a patch to do that so that one should be resolved too.