Bug 2458430 - Review Request: fzssh - SSH/SFTP library based on libfilezilla
Summary: Review Request: fzssh - SSH/SFTP library based on libfilezilla
Keywords:
Status: ASSIGNED
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Artur Frenszek-Iwicki
QA Contact: Fedora Extras Quality Assurance
URL: https://fzssh.filezilla-project.org/
Whiteboard:
Depends On:
Blocks: FE-Legal 2507489 2510962
TreeView+ depends on / blocked
 
Reported: 2026-04-14 19:27 UTC by Gwyn Ciesla
Modified: 2026-08-04 15:00 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Gwyn Ciesla 2026-04-14 19:27:53 UTC
SRPM:https://fedorapeople.org/~limb/review/fzssh/fzssh-1.1.10-1.fc45.src.rpm
SPEC:https://fedorapeople.org/~limb/review/fzssh/fzssh.spec

Description:
fzssh is a SSH/SFTP library based on libfilezilla

Comment 1 Fedora Review Service 2026-04-15 03:24:02 UTC
Copr build:
https://copr.fedorainfracloud.org/coprs/build/10326553
(failed)

Build log:
https://download.copr.fedorainfracloud.org/results/@fedora-review/fedora-review-2458430-fzssh/fedora-rawhide-x86_64/10326553-fzssh/builder-live.log.gz

Please make sure the package builds successfully at least for Fedora Rawhide.

- If the build failed for unrelated reasons (e.g. temporary network
  unavailability), please ignore it.
- If the build failed because of missing BuildRequires, please make sure they
  are listed in the "Depends On" field


---
This comment was created by the fedora-review-service
https://github.com/FrostyX/fedora-review-service

If you want to trigger a new Copr build, add a comment containing new
Spec and SRPM URLs or [fedora-review-service-build] string.

Comment 2 Artur Frenszek-Iwicki 2026-07-24 17:23:56 UTC
This seems to require libfilezilla >= 0.55.3, whereas the version currently in Fedora Rawhide is libfilezilla-0.54.1-2.fc45.
Upstream has 0.56.1 available.

Comment 3 Gwyn Ciesla 2026-07-24 17:57:41 UTC
I can push 0.56.1 but then we should proceed with this quickly as that would be a soname bump and break filezilla in rawhide until this is ready.  Sound ok?

Comment 4 Artur Frenszek-Iwicki 2026-07-24 18:03:55 UTC
Sure thing.

Comment 5 Gwyn Ciesla 2026-07-24 19:29:58 UTC
Ok, updated libfilezilla, and pushed latest fzssh.

SRPM:https://fedorapeople.org/~limb/review/fzssh/fzssh-1.3.0-1.fc45.src.rpm
SPEC:https://fedorapeople.org/~limb/review/fzssh/fzssh.spec

Comment 6 Artur Frenszek-Iwicki 2026-07-26 09:35:53 UTC
Overall it looks okay, just two issues:

1. The source link (https://download.filezilla-project.org/fzssh/fzssh-1.3.0.tar.xz) does not work;
   it gives a 307 Temporary Redirect and then moves you to filezilla's website main page.
   
2. The README mentions some additional restrictions placed on top of AGPLv3:
> Additional Terms under AGPLv3 Section 7 (and corresponding sections in
> future versions):
> 
> Notwithstanding any other provision of this License, for any material you
> use from this library, you must:
> 
> 1. Preserve Attribution: Retain the original copyright notices and author
> attributions in the source code.
> 
> 2. Prominent Documentation Notice: If you distribute or convey the work
> (or any part of it) in binary or object code form, you must include a
> prominent notice in the accompanying documentation and/or "README" files
> stating:
>   This software incorporates components from fzssh, copyright (c) 2025-2026
>   Tim Kosse and Business Follows Srl
> 
> 3. Interactive User Interfaces: If the work possesses an interactive user
> interface, the "Appropriate Legal Notices" (as defined in Section 0) must
> display the copyright attribution to Tim Kosse and Business Follows Srl
> in a prominently visible manner (e.g., in an "About" or "Legal" menu).
This seems to fall squarely under AGPLv3 Section 7b, but still - might be worth running through legal?

Comment 7 Gwyn Ciesla 2026-07-27 15:32:47 UTC
1. The filezilla project uses a cdn and the download url changes with every page refresh. If I specify one cdn host I can get that to work, in this case https://dl3.cdn.filezilla-project.org/fzssh/fzssh-1.3.0.tar.xz.  I could go with that.

2. I'll flag legal. Better safe than sorry.

Comment 8 Richard Fontana 2026-07-27 15:58:21 UTC
This looks surprisingly okay (given the legacy of abuse of AGPLv3 particularly with respect to the "Appropriate Legal Notices" construct) but it should be submitted for review at fedora-license-data since it is not pure AGPLv3.

Comment 9 Gwyn Ciesla 2026-07-27 16:47:18 UTC
Right? Will do, thank you.


Note You need to log in before you can comment on or make changes to this bug.