ceph links against OpenSSL but is GPL/LGPL and has no special exception

Bug #684011 reported by Clint Byrum
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ceph
Fix Released
Undecided
auto-sage
ceph (Ubuntu)
Fix Released
Critical
Clint Byrum
Nominated for Maverick by Clint Byrum

Bug Description

Binary package hint: ceph

The GPL and OpenSSL, unmodified, are incompatible. A simple exception is needed to relax the GPL restrictions that prohibit clauses in the OpenSSL license.

Related branches

Changed in ceph (Ubuntu):
importance: Undecided → Critical
milestone: none → ubuntu-11.04
Revision history for this message
Sage Weil (sage-newdream) wrote :

We've replaced the openssl dependency with libcrypto++ in v0.24.

Revision history for this message
Clint Byrum (clint-fewbar) wrote :

Fix was released upstream, noting that in bug report.

Changed in ceph:
status: New → Fix Released
Changed in ceph (Ubuntu):
status: New → Triaged
assignee: nobody → Clint Byrum (clint-fewbar)
Revision history for this message
Clint Byrum (clint-fewbar) wrote :

This should be fixed by packaging 0.24 or later .. which I will be working on.

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package ceph - 0.24.2-0ubuntu1

---------------
ceph (0.24.2-0ubuntu1) natty; urgency=low

  [ Clint Byrum <email address hidden> ]
  * New upstream release. (LP: #658670, LP: #684011)
  * debian/patches/fix-mkcephfs.patch: dropped (applied upstream)
  * Removed .la files from libceph1-dev, libcrush1-dev and
    librados1-dev (per Debian policy v3.9.1 10.2).
  * debian/control: adding pkg-config as a build dependency
  * debian/control: depend on libcrypto++-dev instead of libssl-dev
  * debian/watch: added watch file

  [ Micah Gersten <email address hidden> ]
  * debian/control: add Homepage
 -- Clint Byrum <email address hidden> Sat, 12 Feb 2011 22:50:26 -0600

Changed in ceph (Ubuntu):
status: Triaged → Fix Released
Revision history for this message
Clint Byrum (clint-fewbar) wrote :

Ok now that a non-ssl-linking version has been uploaded, we need to deal with the licensing situation for the package in maverick.

I'd suggest that we get an exception to the new upstream rule for SRU's and backport the 0.24.2 package to Maverick. Dropping the package will just have the effect of keeping the incompatibly licensed software installed, and denying them access to any future critical updates to it.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.