[Debian-pan-maintainers] Debian NEW review of quanty 0.9.0-1: ACCEPTED
awm at debian.org
awm at debian.org
Tue Oct 6 08:57:32 BST 2026
The Debian NEW review of quanty 0.9.0-1 has been completed.
Decision: ACCEPTED
Reviewer: Andrew McMillan
Review comment:
Hi,
Thanks for fixing all the previously advised issues. This is much better :-)
There are still some relatively minor points that should probably be cleaned up...
debian/copyright is not fully accurate in two places (both verifiable from the tree):
- Missing copyright holder for the erfcx/Faddeeva code in Core/BasicMath/BasicMath_Complex.cpp. Lines ~859–996 embed Steven G. Johnson's erfcx ("written by Steven G. Johnson, October 2012", Comment block at line ~875) and the companion FaddeevaW/FaddeevaW_Im/w_im_y100 functions (same suite, referencing "algorithm 816" / "M. Zaghloul"). This is the well-known MIT-licensed code from the stevengj/Faddeeva repository. Two problems: the file carries no Copyright (c) 2012 Massachusetts Institute of Technology, Steven G. Johnson notice or MIT text (MIT requires reproducing the notice in substantial portions), and debian/copyright's Files: * stanza attributes the whole file to the Quanty contributor list under "CC-BY-4.0 or Expat" with no mention of Johnson/MIT. Since the licence (Expat) is compatible with the catch-all, this is not a DFSG violation, but the holder attribution is wrong/incomplete. Fix: add a Files: Core/BasicMath/BasicMath_Complex.cpp stanza with Copyright: 2012 Massachusetts Institute of Technology, Steven G. Johnson / License: Expat, and ask upstream to restore the notice.
- Journal PDFs and their data are mislumped into the catch-all. debian/copyright Files: * claims every file in the tree is held by "Maurits W. Haverkort and Quanty contributors" under CC-BY-4.0/Expat. That is not supportable for third-party published works shipped in the tree:
- Debug examples/Tutorials/20_NiO_Crystal_Field/NiO_Experiment/ and …/40_NiO_Ligand_Field/NiO_Experiment/: Phys. Rev. B 1998 Alders.pdf, J Synchrotron Rad 2009 Verbeni.pdf, plus companion data (NIXS_dd_JSR_16_469_2009, XAS_L23_PRB_57_11623_1998, RnlNi_Atomic_Hartree_Fock). Copyright for these journal articles belongs to APS/IUCr and their authors, not to the Quanty project, and their redistribution terms are unknown to me (binary, unreadable). The catch-all stanza therefore asserts a licence (CC-BY-4.0/Expat by Quanty) that the copyright holders have not granted.
- Also Debug examples/Tutorials/20_NiO_Crystal_Field/NiO_data.zip (1.5 MB binary data) and the various out.wan / CrF4_WFC / ORCA .out files are data of unverified provenance swept into the same stanza (more a hygiene than a legal point).
- Fix (recommended): Files-Excluded the two NiO_Experiment/ directories (and optionally the .pdf/.zip and debug artifacts), add a Repacksuffix: (the watch already has Dversionmangle: s/\+ds\d+//), so the next repack carries +ds. At minimum, debian/copyright must stop attributing these third-party works to the Quanty contributors.
Also worth noting upstream-side (not a Debian blocker): the top-level LICENSE file says "The full license texts are provided in: LICENSE-CC-BY-4.0, LICENSE-MIT", but neither file exists in the tarball — only LICENSE is present. The Debian debian/copyright documents everything itself, so the package is fine; upstream's own license-file story is broken.
Thanks!
Full review details: https://dfsg-new-queue.debian.org/reviews/quanty
More information about the Debian-pan-maintainers
mailing list