Debian Bug report logs - #567915
iceweasel, iceape, icedove, iceowl: Contains non-free data in the source tarball

version graph

Package: iceweasel; Maintainer for iceweasel is Maintainers of Mozilla-related packages <pkg-mozilla-maintainers@lists.alioth.debian.org>; Source for iceweasel is src:firefox-esr (PTS, buildd, popcon).

Reported by: Mike Hommey <mh+reportbug@glandium.org>

Date: Mon, 1 Feb 2010 07:51:01 UTC

Severity: serious

Fixed in version iceweasel/3.5.9-1

Done: Mike Hommey <glandium@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Maintainers of Mozilla-related packages <pkg-mozilla-maintainers@lists.alioth.debian.org>, Ubuntu Mozilla Team <ubuntu-mozillateam@lists.ubuntu.com>, Alexander Sack <asac@debian.org>:
Bug#567915; Package iceweasel,iceape,icedove,iceowl. (Mon, 01 Feb 2010 07:51:04 GMT) (full text, mbox, link).


Acknowledgement sent to Mike Hommey <mh+reportbug@glandium.org>:
New Bug report received and forwarded. Copy sent to Maintainers of Mozilla-related packages <pkg-mozilla-maintainers@lists.alioth.debian.org>, Ubuntu Mozilla Team <ubuntu-mozillateam@lists.ubuntu.com>, Alexander Sack <asac@debian.org>. (Mon, 01 Feb 2010 07:51:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Mike Hommey <mh+reportbug@glandium.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: iceweasel, iceape, icedove, iceowl: Contains non-free data in the source tarball
Date: Mon, 01 Feb 2010 08:48:40 +0100
Package: iceweasel,iceape,icedove,iceowl
Severity: serious
Justification: DFSG

There are some Firefox logos in:
- toolkit/components/places/tests/unit/
- modules/libpr0n/test/unit/

There are some other images which i really doubt the licencing:
- modules/libpr0n/test/reftest/pngsuite-transparency/
- layout/html/tests/block/bugs/top_middle2.jpg
- layout/html/tests/block/bugs/20020515_60x60_scooby.jpg
- dom/tests/mochitest/dom-level2-html/files/w3c_main.png

etc.

There could also be content problems in the html files in the
test suite, but i haven't checked.

Followup bug upstream:
https://bugzilla.mozilla.org/show_bug.cgi?id=541984

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.31-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash




Bug reassigned from package 'iceweasel,iceape,icedove,iceowl' to 'iceweasel'. Request was from Mike Hommey <glandium@debian.org> to control@bugs.debian.org. (Mon, 01 Feb 2010 08:09:02 GMT) (full text, mbox, link).


Bug 567915 cloned as bug 567917. Request was from Mike Hommey <glandium@debian.org> to control@bugs.debian.org. (Mon, 01 Feb 2010 08:09:03 GMT) (full text, mbox, link).


Bug 567915 cloned as bug 567918. Request was from Mike Hommey <glandium@debian.org> to control@bugs.debian.org. (Mon, 01 Feb 2010 08:09:05 GMT) (full text, mbox, link).


Bug 567915 cloned as bug 567919. Request was from Mike Hommey <glandium@debian.org> to control@bugs.debian.org. (Mon, 01 Feb 2010 08:09:07 GMT) (full text, mbox, link).


Bug 567915 cloned as bug 567920. Request was from Mike Hommey <glandium@debian.org> to control@bugs.debian.org. (Mon, 01 Feb 2010 08:09:09 GMT) (full text, mbox, link).


Bug 567915 cloned as bug 567922. Request was from Mike Hommey <glandium@debian.org> to control@bugs.debian.org. (Mon, 01 Feb 2010 08:18:03 GMT) (full text, mbox, link).


Bug 567915 cloned as bug 572710. Request was from Gabriele Giacone <1o5g4r8o@gmail.com> to control@bugs.debian.org. (Fri, 05 Mar 2010 20:27:05 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Maintainers of Mozilla-related packages <pkg-mozilla-maintainers@lists.alioth.debian.org>:
Bug#567915; Package iceweasel. (Tue, 23 Mar 2010 12:54:03 GMT) (full text, mbox, link).


Acknowledgement sent to Mike Hommey <mh@glandium.org>:
Extra info received and forwarded to list. Copy sent to Maintainers of Mozilla-related packages <pkg-mozilla-maintainers@lists.alioth.debian.org>. (Tue, 23 Mar 2010 12:54:03 GMT) (full text, mbox, link).


Message #24 received at 567915@bugs.debian.org (full text, mbox, reply):

From: Mike Hommey <mh@glandium.org>
To: 567915@bugs.debian.org, 567917@bugs.debian.org, 567918@bugs.debian.org, 567919@bugs.debian.org, 567920@bugs.debian.org, 567922@bugs.debian.org, 572710@bugs.debian.org
Subject: Cleaning up the upstream tarballs
Date: Tue, 23 Mar 2010 13:52:13 +0100
Hi,

I went through the most obvious images and here are my current
conclusions:
- The files in ./modules/libpr0n/test/reftest/pngsuite-transparency/
  are very likely to have been converted from the original NeXT icons
  on NeXT OS. Which means they all need to be removed (including the
  html files, which are the same images converted as html tables)
- Some files in ./testing/performance are of doubtful origin.
- Some files in ./content/xml/tests are of doubtful origin.
- Some files in ./layout/doc are of doubtful origin.
- Some files in ./layout/html/tests are of doubtful origin.
- Images embedded in ./browser/locales/en-US/searchplugins/*.xml are most
  likely non-free.
- The Firefox icons are *not* non-free.
   (See https://bugzilla.mozilla.org/show_bug.cgi?id=541761)

Considering all of the above, considering I didn't want to spend too
much time to track each file's origin and considering most of the above
files are useless to the builds and even the testsuite itself, here is
how I'm going to fix this in xulrunner, iceweasel and iceape:

# rm -fvr ./layout/html/tests
# rm -fvr ./layout/doc
# rm -fvr ./content/xml/tests
# rm -fvr ./testing/performance
# rm -fvr ./modules/libpr0n/test/reftest/pngsuite-transparency/

As I'm now also running reftests on xulrunner, I'll also do the
following:
# sed -i /pngsuite-transparency/d ./modules/libpr0n/test/reftest/reftest.list
which avoids including the removed files in the reftest.

And finally, for the search plugins images, I'm going to do:

# sed -i 's,>data:.*\(</Image>\), type="image/x-icon">http://www.amazon.com/favicon.ico\1,' ./browser/locales/en-US/searchplugins/amazondotcom.xml
# sed -i 's,>data:.*\(</Image>\), type="image/x-icon">http://www.answers.com/favicon.ico\1,' ./browser/locales/en-US/searchplugins/answers.xml
# sed -i 's,>data:.*\(</Image>\), type="image/x-icon">http://www.creativecommons.org/favicon.ico\1,' ./browser/locales/en-US/searchplugins/creativecommons.xml
# sed -i 's,>data:.*\(</Image>\), type="image/x-icon">http://www.ebay.com/favicon.ico\1,' ./browser/locales/en-US/searchplugins/eBay.xml
# sed -i 's,>data:.*\(</Image>\), type="image/x-icon">http://www.google.com/favicon.ico\1,' ./browser/locales/en-US/searchplugins/google.xml
# sed -i 's,>data:.*\(</Image>\), type="image/x-icon">http://en.wikipedia.org/favicon.ico\1,' ./browser/locales/en-US/searchplugins/wikipedia.xml
# sed -i 's,>data:.*\(</Image>\), type="image/x-icon">http://www.yahoo.com/favicon.ico\1,' ./browser/locales/en-US/searchplugins/yahoo.xml

Which replaces the embedded images with links to the icon on the web.
Please note that these files are normally only used by iceweasel, so
you can just apply the changes in the upstream tarball without caring
more.

For iceweasel (xulrunner, actually), however, it is necessary to also
apply the patch from https://bugzilla.mozilla.org/show_bug.cgi?id=554265

Mike

PS: For reference, the upstream bug about the test suite images is:
https://bugzilla.mozilla.org/show_bug.cgi?id=541984




Added tag(s) pending. Request was from Mike Hommey <glandium@debian.org> to control@bugs.debian.org. (Tue, 23 Mar 2010 12:57:04 GMT) (full text, mbox, link).


Reply sent to Mike Hommey <glandium@debian.org>:
You have taken responsibility. (Sat, 03 Apr 2010 15:51:14 GMT) (full text, mbox, link).


Notification sent to Mike Hommey <mh+reportbug@glandium.org>:
Bug acknowledged by developer. (Sat, 03 Apr 2010 15:51:14 GMT) (full text, mbox, link).


Message #31 received at 567915-close@bugs.debian.org (full text, mbox, reply):

From: Mike Hommey <glandium@debian.org>
To: 567915-close@bugs.debian.org
Subject: Bug#567915: fixed in iceweasel 3.5.9-1
Date: Sat, 03 Apr 2010 15:48:52 +0000
Source: iceweasel
Source-Version: 3.5.9-1

We believe that the bug you reported is fixed in the latest version of
iceweasel, which is due to be installed in the Debian FTP archive:

iceweasel-dbg_3.5.9-1_amd64.deb
  to main/i/iceweasel/iceweasel-dbg_3.5.9-1_amd64.deb
iceweasel_3.5.9-1.debian.tar.gz
  to main/i/iceweasel/iceweasel_3.5.9-1.debian.tar.gz
iceweasel_3.5.9-1.dsc
  to main/i/iceweasel/iceweasel_3.5.9-1.dsc
iceweasel_3.5.9-1_amd64.deb
  to main/i/iceweasel/iceweasel_3.5.9-1_amd64.deb
iceweasel_3.5.9.orig.tar.bz2
  to main/i/iceweasel/iceweasel_3.5.9.orig.tar.bz2



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 567915@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Mike Hommey <glandium@debian.org> (supplier of updated iceweasel package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 01 Apr 2010 16:23:51 +0200
Source: iceweasel
Binary: iceweasel iceweasel-dbg
Architecture: source amd64
Version: 3.5.9-1
Distribution: unstable
Urgency: low
Maintainer: Maintainers of Mozilla-related packages <pkg-mozilla-maintainers@lists.alioth.debian.org>
Changed-By: Mike Hommey <glandium@debian.org>
Description: 
 iceweasel  - Web browser based on Firefox
 iceweasel-dbg - debugging symbols for iceweasel
Closes: 561927 567915
Changes: 
 iceweasel (3.5.9-1) unstable; urgency=low
 .
   * New upstream release.
   * config/autoconf.mk.in: Revert previous changes to install in an
     unversioned directory.
   * debian/rules: Pass an installdir variable to install into
     /usr/lib/iceweasel.
   * debian/control:
     - Suggest libkrb53 for backports.
     - Build-depend on xulrunner-dev << 1.9.2.
   * debian/iceweasel.prerm, debian/iceweasel.postinst: Remove old mozilla
     alternative. I think there is no reason to keep this anymore.
   * debian/iceweasel.links: Remove firefox and mozilla-firefox links.
     It will help make transition to Firefox easier if that ever happens.
   * debian/remove.nonfree: We now remove more non-free data. Also cleaned up
     outdated stuff. Closes: #567915
   * debian/source/format, debian/patches/*: Switch to 3.0 (quilt) format,
     with patches.
 .
   * browser/components/safebrowsing/content/application.js,
     browser/app/profile/firefox.js: Use googpub-phish-shavar instead of
     goog-phish-shavar for safe browsing. This is a first step for fixing safe
     browsing. Either the current setup will work if Google allows our client
     string to get this data, or we'll be allowed to say we're firefox to the
     safe browsing server. Closes: #561927.
Checksums-Sha1: 
 7d3d840227cafd396940e930074b2f8e5bc88e9f 1503 iceweasel_3.5.9-1.dsc
 6249055288abb9e48ef52a96aacaeed0397a3dd9 41145864 iceweasel_3.5.9.orig.tar.bz2
 40c2f201f9b10a63a81bb564a049376d6ecd7cf6 146430 iceweasel_3.5.9-1.debian.tar.gz
 e0e161d3ff1677dcc1f2ad9b5128d5eca13f76b5 1106244 iceweasel_3.5.9-1_amd64.deb
 7b5ebd5afc29afa3128fa706e8e83a884e58353c 461846 iceweasel-dbg_3.5.9-1_amd64.deb
Checksums-Sha256: 
 5938e6a436fb69e1cd5d17149ff3eb6cb5fe7ae4838c3e654f84324dfd55350f 1503 iceweasel_3.5.9-1.dsc
 5d7d87e1155b76ecb226e48fa0f1a8eee286c3fab893118cc8641b6e6f87b1cc 41145864 iceweasel_3.5.9.orig.tar.bz2
 a24037c3cb8c5584cfc1697edaad679788a5a60767dd09a1e9accabde8769fd5 146430 iceweasel_3.5.9-1.debian.tar.gz
 390e131cea61a7908efc750ecb367fae7a0fbb6e9345aea4995dca552217fa5b 1106244 iceweasel_3.5.9-1_amd64.deb
 c41c2d755c2210b34e26e80383131d944c212a59f1baa6e5b4a522985676daf2 461846 iceweasel-dbg_3.5.9-1_amd64.deb
Files: 
 e93316635426ccdf30544bee47df9cbd 1503 web optional iceweasel_3.5.9-1.dsc
 9bbbf139243de9f7262cf1b56f679b5e 41145864 web optional iceweasel_3.5.9.orig.tar.bz2
 3c9faf26bbb3064326f70f63ac12f75d 146430 web optional iceweasel_3.5.9-1.debian.tar.gz
 e826f7b25a7ef4cf7bc7200b5a9083f2 1106244 web optional iceweasel_3.5.9-1_amd64.deb
 3569afe02a23afe4b33cb2fe115b6295 461846 debug extra iceweasel-dbg_3.5.9-1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iD8DBQFLtLnu3kvaLFT9KlgRAnJZAJ40uEKGoqcKxgOzF4kUxeTchjfrLgCeKZSY
qVl71HEEKBoEIUtIX4mdTE4=
=pqnH
-----END PGP SIGNATURE-----





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 23 May 2010 07:32:02 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sun Jan 7 09:33:02 2018; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.