Bug 8197 - gmp license leads to gnutls being effectively LGPL3
Summary: gmp license leads to gnutls being effectively LGPL3
Status: VERIFIED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: core (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium+ normal
Target Milestone: 1.9 M3
Assignee: Jussi Kukkonen
QA Contact: Daniel Istrate
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2015-08-21 11:53 UTC by Jussi Kukkonen
Modified: 2015-10-01 11:58 UTC (History)
4 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: Regression (Used to work)
Verified:
Documentation change: Don't know


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jussi Kukkonen 2015-08-21 11:53:53 UTC
gnutls depends on nettle which depends on gmp. gnutls is LGPLv2 but our version of gmp is dual-licensed "LGPLv3+ | GPLv2+" making that the effective license for gnutls as well. This is undesirable for many oe-core users.

The LGPLv2 version of gmp was mistakenly removed here (poky commit id):

| commit 25bf76a8668d2572c6f1a396b657e795b031bbb3
| Author: Roy Li <rongqing.li@windriver.com>
| Date:   Tue Aug 12 14:33:37 2014 +0800
| 
|     gmp: uprev it to 6.0.0
|     
|     Uprev gmp from 5.1.1 to 6.0.0, and remove the 4.2.1 version which
|     is GPLv2, since gmp-6.0.0 is dual-licensing, LGPLv3 or GPLv2;
|     
|     (From OE-Core rev: f181c6ce8b364fbf761a456d998ab78fbd751f35)

The comment is incorrect: 4.2.1 license was LGPLv2, not GPLv2.


Three solutions that I can see:
1. bring back gmp 4.2.1. We can soon celebrate its 10th birthday so
   it might not be in great shape. Keep maintaining (and testing)
   old nettle and gmp along with new versions.
2. Fix gnutls configure option "--with-nettle-mini": this should use
   a internal copy of nettle and gmp, but seems to fail to build...
   I'm not convinced that it's ever worked properly: it seems to require
   actual nettle headers to be installed.
3. Keep following upstream gmp and nettle, accept that gnutls is now
   effectively LGPLv3

I'll probably have a go at option #1 (and maybe ask gnutls people about option #2). Can't say I'm super happy about either option -- security related code that is A) unmaintained for years and B) not used by anyone else is not a great choice.

Please let me know if #3 is actually something we can consider at this point...
Comment 1 Jussi Kukkonen 2015-08-26 13:35:35 UTC
For the generic problem of "The GNU default license 'LGPLv3|GPLv2' confuses 'non-gpl3' builds" see bug 8158.
Comment 2 Jussi Kukkonen 2015-09-04 07:30:04 UTC
Fixed in master. I don't know if the correct version will be picked up by the non-gpl3 autobuilder though, but I'll keep an eye out on that in bug 8158.



commit 6fac60da96eee89d5b7c2156bbb92fe72dc28aef
Author: Jussi Kukkonen <jussi.kukkonen@intel.com>
Date:   Thu Aug 27 16:05:59 2015 +0300

    gmp: Bring back version 4.2.1 (LGPL 2.1+)
    
    gmp 4.2.1 was removed in f181c6ce8b apparently accidentally: It
    was not noticed that 4.2.1 is LGPL 2.1 (and not GPL) so provides
    a useful alternative to the newer "GPLv2 | LGPLv3" version.
    
    * Reintroduce 4.2.1. The source includes files that are GPL but the
      library package is LGPL 2.1+
    * Also reintroduce the two patches removed in f181c6ce8b.
    * Refactor gmp.inc: gmp 6.0.0 build should not be affected in any way.
    * Update 6.0.0 license from "GPLv2 | LGPLv3" to "GPLv2+ | LGPLv3+".
    
    [YOCTO #8197]
    
    (From OE-Core rev: 1adec83621f36a3dd748990c307ca4ebebcdd554)
    
    Signed-off-by: Jussi Kukkonen <jussi.kukkonen@intel.com>
    Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Comment 3 Daniel Istrate 2015-10-01 11:58:43 UTC
Verified on master: 979de7703cf3e468aa2923da1445138e1c93d234

Steps to verify:
1. Add to local.conf --> PREFERRED_VERSION_gmp = "4.2.1"
2. bitbake -e gmp |grep ^LICENSE= --> LICENSE="LGPLv2.1+ & GPLv2+"
3. bitbake core-image-full-cmdline (or gnutls or another image)
4. Open tmp/deploy/licenses/core-image-full-cmdline-qemux86-20151001110915/license.manifest and look for: 
PACKAGE NAME: gmp
PACKAGE VERSION: 4.2.1
RECIPE NAME: gmp
LICENSE: LGPLv2.1+ <-- license should be LGPLv2.1
5. cat tmp/deploy/licenses/core-image-full-cmdline-qemux86-20151001110915/package.manifest | grep gnutls
libgnutls-openssl27
libgnutls28  <-- gnutls still builds