1 |
On Thu, 7 Sep 2017 15:04:34 +0200 Ulrich Mueller wrote: |
2 |
> >>>>> On Thu, 7 Sep 2017, Rich Freeman wrote: |
3 |
> |
4 |
> >>> Do we routinely confirm that any site we list in SRC_URI has |
5 |
> >>> permission to redistribute files? That seems like a slippery |
6 |
> >>> slope. |
7 |
> >> |
8 |
> >> We don't, and for a package that comes with a license (as the vast |
9 |
> >> majority of packages does) it normally isn't necessary. |
10 |
> |
11 |
> > Why isn't this necessary? How do you know the person issuing the |
12 |
> > license actually has the right to issue it? |
13 |
> |
14 |
> Don't you think there is a difference between downloading a package |
15 |
> that has a known upstream and that is also carried by other distros, |
16 |
> and downloading a license-less package from a random location on the |
17 |
> internet? |
18 |
|
19 |
If downloaded files are the same (e.g. sha512 hash matches), what's |
20 |
the difference? |
21 |
|
22 |
Best regards, |
23 |
Andrew Savchenko |