Bug 967736

Summary: nodejs SRPM contains patented code
Product: [Fedora] Fedora Reporter: Michal Srb <msrb>
Component: nodejsAssignee: T.C. Hollingsworth <tchollingsworth>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: rawhideCC: jamielinux, mrunge, sgallagh, tchollingsworth, thrcka
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Unspecified   
Whiteboard:
Fixed In Version: libuv-0.10.9-1.el6 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-06-08 03:39:54 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Michal Srb 2013-05-28 08:07:56 UTC
Description of problem:

Upstream tarball contains source code of nodejs dependencies, including openssl. openssl sources contain some patented code (RC5, EC, possibly more). I think that Fedora should distribute nodejs SRPM without those patented parts.

Comment 1 T.C. Hollingsworth 2013-05-29 02:44:58 UTC
Luckily we don't use the bundled code at all so we can just delete the bundled copy of OpenSSL wholesale, avoiding the need to keep track of what's okay and what's not.  I'm going to push a 0.10.7 update soon and I'll make sure the tarball is stripped for that update.

Comment 2 Fedora Update System 2013-05-29 06:23:38 UTC
v8-3.14.5.10-1.fc19,libuv-0.10.8-1.fc19,nodejs-0.10.8-1.fc19 has been submitted as an update for Fedora 19.
https://admin.fedoraproject.org/updates/v8-3.14.5.10-1.fc19,libuv-0.10.8-1.fc19,nodejs-0.10.8-1.fc19

Comment 3 Fedora Update System 2013-05-29 06:24:55 UTC
v8-3.14.5.10-1.fc18,libuv-0.10.8-1.fc18,nodejs-0.10.8-1.fc18 has been submitted as an update for Fedora 18.
https://admin.fedoraproject.org/updates/v8-3.14.5.10-1.fc18,libuv-0.10.8-1.fc18,nodejs-0.10.8-1.fc18

Comment 4 Fedora Update System 2013-05-29 06:26:16 UTC
v8-3.14.5.10-1.el6,libuv-0.10.8-1.el6,nodejs-0.10.8-1.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/v8-3.14.5.10-1.el6,libuv-0.10.8-1.el6,nodejs-0.10.8-1.el6

Comment 5 Fedora Update System 2013-05-29 17:33:51 UTC
Package libuv-0.10.8-2.el6, v8-3.14.5.10-1.el6, nodejs-0.10.8-1.el6:
* should fix your issue,
* was pushed to the Fedora EPEL 6 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=epel-testing libuv-0.10.8-2.el6 v8-3.14.5.10-1.el6 nodejs-0.10.8-1.el6'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2013-6006/v8-3.14.5.10-1.el6,libuv-0.10.8-2.el6,nodejs-0.10.8-1.el6
then log in and leave karma (feedback).

Comment 6 Fedora Update System 2013-06-08 03:39:54 UTC
libuv-0.10.9-1.fc19, nodejs-0.10.9-1.fc19, v8-3.14.5.10-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2013-06-11 09:15:40 UTC
v8-3.14.5.10-1.fc18, libuv-0.10.9-1.fc18, nodejs-0.10.9-1.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2013-06-19 21:34:28 UTC
libuv-0.10.9-1.el6, nodejs-0.10.9-1.el6, v8-3.14.5.10-1.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.