Re: license chaos, PHP vs GPL

From: Date: Thu, 14 Feb 2008 16:27:24 +0000
Subject: Re: license chaos, PHP vs GPL
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-49159@lists.php.net to get a copy of this message
> Hi, > > we currently bundle a bunch of PEAR packages with RoundCube (1) and > this has lead to some complications - especially with Debian in the > past. (Just for the record: No offense to the Debian people! :-)) > >>From the little I understand about licenses, BSD and GPL get along > much better, correct? The complications come from the PHP license > (PEAR, Net_SMTP, DB) and GPL license (which is RoundCube). RoundCube's > install practice pretty much follows the (infamous) "unzip & go" > approach (well, "unzip, edit two config files & go"), which is also > why we bundle all dependencies. > > Obviously we can (and will) replace DB with MDB2 which gets rid off > one of the items causing the trouble, but what would be the best > approach to work with Net_SMTP and PEAR? No questions asked it is > great code :-), we rely on it heavily and at least for the next > release we can't throw them out and replace it right away. Even if we > somehow got rid off Net_SMTP, the PEAR dependency persists through > MDB2. > > My second question is - is it generally discouraged to bundle PEAR > packages? I've never heard of that and see it as common practice in a > lot of OSS which relies on packages from PEAR. But someone raised > their concerns that this is the case. > > Of course we could "just" let our users install the packages required > but personally I want to avoid that as this will (I assume) at least > tripple support requests on our side. And I think that I can make this > assumption from the daily chats in #pear. > > In the past RoundCube did multiple editions per release - one standard > (I like to call it the "happy meal") and one without dependencies all > dependencies. > > Food for thoughts? I'd be interested to hear how others (would) solve > a similar situation. Speaking as the Fedora maintainer, and thus a representative of possibly the most license-conscious distro, I think you need to distribute: A: One version with no deps. This follows the GPL and is the most legally correct option. B: One version with deps and one without. This is legally dubious but allows for one-stop installs. C: One version with deps, but that will still work if the deps are removed from the tarball and are installed on the system via rpms, debs, etc. This is also legally dubious but will let Fedora do it's thing. Currently, rc2 is broken if the deps are removed. Jon > Thanks, > Till > > P.S. > Please keep Thomas and Jon CC'ed on your replies. They don't read > pear-dev@. > > 1, http://roundcube.net > -- novus ordo absurdum

« previous php.pear.dev (#49159) next »