gnutls depends on nettle which depends on gmp. gnutls is LGPLv2 but our version of gmp is dual-licensed "LGPLv3+ | GPLv2+" making that the effective license for gnutls as well. This is undesirable for many oe-core users. The LGPLv2 version of gmp was mistakenly removed here (poky commit id): | commit 25bf76a8668d2572c6f1a396b657e795b031bbb3 | Author: Roy Li <rongqing.li@windriver.com> | Date: Tue Aug 12 14:33:37 2014 +0800 | | gmp: uprev it to 6.0.0 | | Uprev gmp from 5.1.1 to 6.0.0, and remove the 4.2.1 version which | is GPLv2, since gmp-6.0.0 is dual-licensing, LGPLv3 or GPLv2; | | (From OE-Core rev: f181c6ce8b364fbf761a456d998ab78fbd751f35) The comment is incorrect: 4.2.1 license was LGPLv2, not GPLv2. Three solutions that I can see: 1. bring back gmp 4.2.1. We can soon celebrate its 10th birthday so it might not be in great shape. Keep maintaining (and testing) old nettle and gmp along with new versions. 2. Fix gnutls configure option "--with-nettle-mini": this should use a internal copy of nettle and gmp, but seems to fail to build... I'm not convinced that it's ever worked properly: it seems to require actual nettle headers to be installed. 3. Keep following upstream gmp and nettle, accept that gnutls is now effectively LGPLv3 I'll probably have a go at option #1 (and maybe ask gnutls people about option #2). Can't say I'm super happy about either option -- security related code that is A) unmaintained for years and B) not used by anyone else is not a great choice. Please let me know if #3 is actually something we can consider at this point...
For the generic problem of "The GNU default license 'LGPLv3|GPLv2' confuses 'non-gpl3' builds" see bug 8158.
Fixed in master. I don't know if the correct version will be picked up by the non-gpl3 autobuilder though, but I'll keep an eye out on that in bug 8158. commit 6fac60da96eee89d5b7c2156bbb92fe72dc28aef Author: Jussi Kukkonen <jussi.kukkonen@intel.com> Date: Thu Aug 27 16:05:59 2015 +0300 gmp: Bring back version 4.2.1 (LGPL 2.1+) gmp 4.2.1 was removed in f181c6ce8b apparently accidentally: It was not noticed that 4.2.1 is LGPL 2.1 (and not GPL) so provides a useful alternative to the newer "GPLv2 | LGPLv3" version. * Reintroduce 4.2.1. The source includes files that are GPL but the library package is LGPL 2.1+ * Also reintroduce the two patches removed in f181c6ce8b. * Refactor gmp.inc: gmp 6.0.0 build should not be affected in any way. * Update 6.0.0 license from "GPLv2 | LGPLv3" to "GPLv2+ | LGPLv3+". [YOCTO #8197] (From OE-Core rev: 1adec83621f36a3dd748990c307ca4ebebcdd554) Signed-off-by: Jussi Kukkonen <jussi.kukkonen@intel.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Verified on master: 979de7703cf3e468aa2923da1445138e1c93d234 Steps to verify: 1. Add to local.conf --> PREFERRED_VERSION_gmp = "4.2.1" 2. bitbake -e gmp |grep ^LICENSE= --> LICENSE="LGPLv2.1+ & GPLv2+" 3. bitbake core-image-full-cmdline (or gnutls or another image) 4. Open tmp/deploy/licenses/core-image-full-cmdline-qemux86-20151001110915/license.manifest and look for: PACKAGE NAME: gmp PACKAGE VERSION: 4.2.1 RECIPE NAME: gmp LICENSE: LGPLv2.1+ <-- license should be LGPLv2.1 5. cat tmp/deploy/licenses/core-image-full-cmdline-qemux86-20151001110915/package.manifest | grep gnutls libgnutls-openssl27 libgnutls28 <-- gnutls still builds