Bug #63520 [Com]: JSON extension includes a problematic license statement

From: Date: Wed, 18 Jun 2014 17:35:41 +0000
Subject: Bug #63520 [Com]: JSON extension includes a problematic license statement
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186241@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=63520&edit=1

 ID:                 63520
 Comment by:         php at josediazgonzalez dot com
 Reported by:        kaplan at debian dot org
 Summary:            JSON extension includes a problematic license
                     statement
 Status:             Assigned
 Type:               Bug
 Package:            JSON related
 PHP Version:        Irrelevant
 Assigned To:        remi
 Block user comment: N
 Private report:     N

 New Comment:

I'd like to note that this issue has caused a few bugs within the distros themselves. Ubuntu
now packages pecl-json-c as an alias for php5-json. The package is a valiant effort, but is
unfortunately incompatible with the version bundled with PHP.

The pecl-json-c version improperly parses non-utf8 characters. In the process of upgrading from one
LTS of Ubuntu (12.04) to another (14.04), we uncovered this issue after test runs. I've filed a
bug against the readme of that repository - and am attempting to setup automated testing so that we
can potentially whittle away at the issue - but I cannot currently suggest it as a valid alternative
to the built-in json integration. Hopefully I can get tests going and we can change that situation.

Unfortunately, all PPAs and external repositories for Ubuntu 14.04 appear to have this same issue,
so the fix is currently (pending some tests of course, I haven't created a debian package in a
few months so this is all from a cursory glance):

- apt-get source php5
- Remove the dfsg-repack.sh. This file is the file which removes ext-json (why they didn't just
change the compile options I don't know, but I'm sure there is a good reason)
- Add php5-json to the provides and conflicts stanzas of php5-common in the debian/control file
- Remove php5-json from the depends and breaks stanzas of php5-common in the debian/control file
- Change the version in the debian/changelog file.
- Run debuild -us -uc -b

Hopefully this helps someone else in my shoes. I also wonder why they didn't remove
sqlite/sqlite3, as the copyright there is a blessing with similar language ;)


Previous Comments:
------------------------------------------------------------------------
[2014-04-17 16:46:33] fleshgrinder at gmx dot at

If the original source code stays within the PHP code the complete PHP license is invalidated,
that's a serious bug in my opinion. But seems like nearly nobody else from the PHP group sees
this problem. In the end it's the same as taking some proprietary code from {{Company X}} and
simply reshipping it with your own license. Whoever thinks that {{Company X}} would be happy about
this, think again...

https://github.com/remicollet/pecl-json-c
seems to be a great drop-in with comment support for JSON files which is great in my opinion.
Something that JSON should have supported from the very first release.

------------------------------------------------------------------------
[2014-01-30 05:10:23] rasmus@php.net

Tim, if you had upgraded from the version provided by php.net you would not have seen a problem. We
have not removed json and we will never release a version of php without json support built in. Any
changes in 5.5 is due to whatever distro packaging you are using which we have no control over.

------------------------------------------------------------------------
[2014-01-29 23:59:52] tim at vanillaforums dot com

I think I speak for most PHP end users when I say I *literally* couldn't care less what
underlying JSON implementation is used in the end, as long as the json_* functions remain core,
default-enabled functions.

The utter childishness of some of the comments in this thread gives me a non-trivial level of
concern, but I'm hoping we don't enter a future where json_* cannot be relied on to exist.

Yesterday a co-worker upgraded to PHP 5.5 and found that he was missing these vital functions. The
revelation that THIS of all things was the cause left us speechless.

------------------------------------------------------------------------
[2013-12-27 21:10:52] scott at arciszewski dot me

I definitely would like to encourage the adoption of https://github.com/remicollet/pecl-json-c in
all distributions of PHP if for no other reason than the JSON_PARSER_NOTSTRICT option:
* comments are allowed in json string/files (Using /* */ or // until end of line)

This would allow the use of commented JSON configuration files, which is awesome.

------------------------------------------------------------------------
[2013-08-30 18:12:46] jsjohnst@php.net

When the decision is made, can we get a public statement on the site about it? 
Posts like the one on iteration99 (dot) com are only raising the confusion level 
among devs when really this isn't something directly impacting most PHP 
developers.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=63520


--
Edit this bug report at https://bugs.php.net/bug.php?id=63520&edit=1


Thread (40 messages)

« previous php.bugs (#186241) next »