Debian Bug report logs - #657244
batik bundles a non free colour profile in pdf-transcoder.jar

version graph

Package: batik; Maintainer for batik is Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>;

Reported by: Karl Goetz <karl@kgoetz.id.au>

Date: Tue, 24 Jan 2012 23:06:02 UTC

Severity: serious

Fixed in version batik/1.7+dfsg-1

Done: Vincent Fourmond <fourmond@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>:
Bug#657244; Package batik. (Tue, 24 Jan 2012 23:06:05 GMT) Full text and rfc822 format available.

Acknowledgement sent to Karl Goetz <karl@kgoetz.id.au>:
New Bug report received and forwarded. Copy sent to Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>. (Tue, 24 Jan 2012 23:06:05 GMT) Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: Karl Goetz <karl@kgoetz.id.au>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: batik bundles a non free colour profile in pdf-transcoder.jar
Date: Wed, 25 Jan 2012 09:54:40 +1100
[Message part 1 (text/plain, inline)]
Package: batik
Severity: serious
Justification: may not be distributed without fee if modified
User: gnewsense-dev@nongnu.org
Usertags: gnewsense libreplanet

Hi,
>From [1], it seems the pdf-transcoder.jar in batik contains a colour  
profile with a crazy licence.
 "...permission to use, copy and distribute this file for any purpose is
 hereby granted without fee, provided that the file is not changed
 including the HP copyright notice tag, ... "

The file will need to be removed from the jar, or the jar (and pdf
support) removed from batik :/

[1] https://savannah.nongnu.org/bugs/?34579
thanks,
kk


-- System Information:
Debian Release: 6.0.3
  APT prefers stable
  APT policy: (990, 'stable')
Architecture: i386 (i686)

Kernel: Linux 2.6.32-5-686-bigmem (SMP w/2 CPU cores)
Locale: LANG=en_AU.utf8, LC_CTYPE=en_AU.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

-- 
Karl Goetz, (Kamping_Kaiser / VK7FOSS)
http://www.kgoetz.id.au
No, I won't join your social networking group
[signature.asc (application/pgp-signature, attachment)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>:
Bug#657244; Package batik. (Wed, 25 Jan 2012 08:00:03 GMT) Full text and rfc822 format available.

Acknowledgement sent to Vincent Fourmond <fourmond@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>. (Wed, 25 Jan 2012 08:00:04 GMT) Full text and rfc822 format available.

Message #10 received at 657244@bugs.debian.org (full text, mbox):

From: Vincent Fourmond <fourmond@debian.org>
To: Karl Goetz <karl@kgoetz.id.au>, 657244@bugs.debian.org
Cc: control@bugs.debian.org
Subject: Re: Bug#657244: batik bundles a non free colour profile in pdf-transcoder.jar
Date: Wed, 25 Jan 2012 08:57:24 +0100
clone 657244 -1
reassign -1 fop
found -1 fop/1:1.0.dfsg2-6
retitle -1 src/java/org/apache/fop/pdf/ sRGB Color Space Profile.icm is non-free
thanks

On Tue, Jan 24, 2012 at 11:54 PM, Karl Goetz <karl@kgoetz.id.au> wrote:
> >From [1], it seems the pdf-transcoder.jar in batik contains a colour
> profile with a crazy licence.
>  "...permission to use, copy and distribute this file for any purpose is
>  hereby granted without fee, provided that the file is not changed
>  including the HP copyright notice tag, ... "
>
> The file will need to be removed from the jar, or the jar (and pdf
> support) removed from batik :/

  Actually, it's more annoying than this. As far as I can tell, batik
doesn't use this binary jar (and it should have been stripped from the
debian source ages ago). Unfortunately, the jar comes from fop, and
the incriminated file is present in fop source, which makes it
unsuitable for main...

  Thanks for your report,

      Vincent




Bug 657244 cloned as bug 657281. Request was from Vincent Fourmond <fourmond@debian.org> to control@bugs.debian.org. (Wed, 25 Jan 2012 08:00:04 GMT) Full text and rfc822 format available.

Information forwarded to debian-bugs-dist@lists.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>:
Bug#657244; Package batik. (Wed, 25 Jan 2012 21:06:03 GMT) Full text and rfc822 format available.

Acknowledgement sent to Karl Goetz <karl@kgoetz.id.au>:
Extra info received and forwarded to list. Copy sent to Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>. (Wed, 25 Jan 2012 21:06:08 GMT) Full text and rfc822 format available.

Message #17 received at 657244@bugs.debian.org (full text, mbox):

From: Karl Goetz <karl@kgoetz.id.au>
To: Vincent Fourmond <fourmond@debian.org>
Cc: 657244@bugs.debian.org
Subject: Re: Bug#657244: batik bundles a non free colour profile in pdf-transcoder.jar
Date: Thu, 26 Jan 2012 07:34:13 +1100
[Message part 1 (text/plain, inline)]
On Wed, 25 Jan 2012 08:57:24 +0100
Vincent Fourmond <fourmond@debian.org> wrote:

> On Tue, Jan 24, 2012 at 11:54 PM, Karl Goetz <karl@kgoetz.id.au>
> wrote:
> > >From [1], it seems the pdf-transcoder.jar in batik contains a
> > >colour
> > profile with a crazy licence.
> >  "...permission to use, copy and distribute this file for any
> > purpose is hereby granted without fee, provided that the file is
> > not changed including the HP copyright notice tag, ... "
> >
> > The file will need to be removed from the jar, or the jar (and pdf
> > support) removed from batik :/
> 
>   Actually, it's more annoying than this. As far as I can tell, batik
> doesn't use this binary jar (and it should have been stripped from the
> debian source ages ago). Unfortunately, the jar comes from fop, and
> the incriminated file is present in fop source, which makes it
> unsuitable for main...

Thanks for tracking down the real source of the problem!
kk

-- 
Karl Goetz, (Kamping_Kaiser / VK7FOSS)
http://www.kgoetz.id.au
No, I won't join your social networking group
[signature.asc (application/pgp-signature, attachment)]

Reply sent to Vincent Fourmond <fourmond@debian.org>:
You have taken responsibility. (Mon, 12 Mar 2012 20:48:19 GMT) Full text and rfc822 format available.

Notification sent to Karl Goetz <karl@kgoetz.id.au>:
Bug acknowledged by developer. (Mon, 12 Mar 2012 20:48:20 GMT) Full text and rfc822 format available.

Message #22 received at 657244-close@bugs.debian.org (full text, mbox):

From: Vincent Fourmond <fourmond@debian.org>
To: 657244-close@bugs.debian.org
Subject: Bug#657244: fixed in batik 1.7+dfsg-1
Date: Mon, 12 Mar 2012 20:47:38 +0000
Source: batik
Source-Version: 1.7+dfsg-1

We believe that the bug you reported is fixed in the latest version of
batik, which is due to be installed in the Debian FTP archive:

batik_1.7+dfsg-1.debian.tar.gz
  to main/b/batik/batik_1.7+dfsg-1.debian.tar.gz
batik_1.7+dfsg-1.dsc
  to main/b/batik/batik_1.7+dfsg-1.dsc
batik_1.7+dfsg.orig.tar.xz
  to main/b/batik/batik_1.7+dfsg.orig.tar.xz
libbatik-java_1.7+dfsg-1_all.deb
  to main/b/batik/libbatik-java_1.7+dfsg-1_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 657244@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Vincent Fourmond <fourmond@debian.org> (supplier of updated batik package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Mon, 12 Mar 2012 20:53:43 +0100
Source: batik
Binary: libbatik-java
Architecture: source all
Version: 1.7+dfsg-1
Distribution: unstable
Urgency: low
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Vincent Fourmond <fourmond@debian.org>
Description: 
 libbatik-java - xml.apache.org SVG Library
Closes: 657244
Changes: 
 batik (1.7+dfsg-1) unstable; urgency=low
 .
   * Provide a repackaged tarball stripping all binary jars (closes: #657244)
     - updated debian/new-upstream as a consequence
   * Disable the installation of batik-js.jar, that wasn't built from sources
     (it was a subset of rhino's js.jar)
   * Conforms to standards 3.9.3
   * Modernize a bit debian/copyright
Checksums-Sha1: 
 a037a23a847e99d867c3143ec9679713ac7e2a4b 1629 batik_1.7+dfsg-1.dsc
 b9e8d2bdedcb1ddf553c9b99115165264cf8b4b8 4290288 batik_1.7+dfsg.orig.tar.xz
 e18997c3d32339dd8547af4bad05f893d7001608 11745 batik_1.7+dfsg-1.debian.tar.gz
 7ae27337d3524ae591c33e355debfa6182f4e5a2 8699110 libbatik-java_1.7+dfsg-1_all.deb
Checksums-Sha256: 
 9148f1a55c2873382844877098ff2868ddb53b60d1368b1da94871235dffae99 1629 batik_1.7+dfsg-1.dsc
 2003bc124a01cedb1ebebda32c1412a0a8292573348d751f8b06fa24dcf03124 4290288 batik_1.7+dfsg.orig.tar.xz
 4ac102a42688b8927f706d40f25ebb3cbad2e437981ad6a8175dcbbcab2a0d37 11745 batik_1.7+dfsg-1.debian.tar.gz
 68bb0699dd5586b329c3c1b4abffbea0d5253ba798baad4fd9845135ff1b7c17 8699110 libbatik-java_1.7+dfsg-1_all.deb
Files: 
 ed709233f4db7bb46ed6906851a138cf 1629 java optional batik_1.7+dfsg-1.dsc
 dfd317fa0c7bc9782273c05d3045b90c 4290288 java optional batik_1.7+dfsg.orig.tar.xz
 6087ec01ceb7173459d824a51e315cee 11745 java optional batik_1.7+dfsg-1.debian.tar.gz
 fe7d656a171d8d1f79b13144320157a1 8699110 java optional libbatik-java_1.7+dfsg-1_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAk9eVOkACgkQx/UhwSKygsosogCghJTNfC8bJUa306ZjknQTj6cZ
6/IAnA2lZ9KqegMW2Cs1dk5wSTc+/fLG
=bocx
-----END PGP SIGNATURE-----





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 02 Jun 2013 07:55:48 GMT) Full text and rfc822 format available.

Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Apr 16 08:06:07 2014; Machine Name: buxtehude.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.