nestopia_2.0.0-1_amd64.changes REJECTED
Andrew McMillan
awm at debian.org
Mon Sep 28 11:00:16 BST 2026
Hi,
I've broken the issues into DFSG-issues and Packaging issues. While various of these are minor, not all of them are, and overall they contribute to a reject. I'm fairly easily persuaded that some of these have to be the way they are because of ... so by all means explain to
Licensing / DFSG
================
1. The shipped binary bundles QTea, but debian/copyright never accounts for it (main issue).
The nestopia binary is not just Nestopia — it's a static build of the QTea frontend with the Nestopia core linked in (debian/rules:30-31 builds from /usr/share/qtea via qtea-src). Yet debian/copyright only covers *, nes_ntsc/*, and debian/* (lines 5-18). QTea is a separate project with its own copyright holders/license, and since it's statically linked into the distributed binary, the actual effective license of the shipped artifact is undocumented. This matters for DFSG: if QTea is e.g. GPL-3.0-only, the combination with the GPL-2.0-or-later core is only possible by relicensing the whole to GPL-3.0, and the copyright file should say so. As written, the licensing documentation is incomplete for the actual binary being distributed.
Since QTea is in Debian now (as of a few days ago) this should use the Debian version of QTea.
2. nes_ntsc/test.bmp (62 KB binary) has undocumented provenance.
It's swept under the nes_ntsc LGPL-2.1+ claim (debian/copyright:12-14), but a binary test image has no license/provenance info in-tree, so it can't be confirmed as free. Worth verifying it isn't a copyrighted screenshot before considering the source DFSG-clean.
ROr you can just exclude it, if that's all too hard and the screenshot doesn't have great value.
3. jg_compat.h (top-level) is from the separate Jolly Good API project and has no copyright/license header.
debian/copyright:5-10 claims it under GPL-2.0+ via the Files: * glob without verification. Minor, but a bundled third-party header whose license is unverified.
Since JG is also in Debian that copyright should be known, or - potentially - a build dependency.
Packaging quality
=================
4. Stale upstream metadata / homepage.
debian/upstream/metadata points to github.com/rdanbrook/nestopia (Repository, Repository-Browse, Bug-Database), but the project has moved — debian/watch:3 and README both say the repo now lives at gitlab.com/jgemu/nestopia. Similarly, Homepage: in debian/control:12 still references the old 0ldsk00l.ca site. The metadata was not updated for the 2.0.0 Jolly Good transition.
5. debian/rules:30 uses mkdir build without -p.
Fails if build/ already exists. It's nominally covered by debian/clean, but mkdir -p would be more robust.
6. Inconsistent doc-file cleanup.
The upstream DOCS (ChangeLog, COPYING, README — Makefile) are pruned three different ways: ChangeLog via debian/not-installed, COPYING/LICENSES via manual rm in debian/rules:39-41. Works, but the approach is inconsistent.
7. debian/nestopia.install:3 explicitly installs usr/share/doc.
Debhelper already handles the doc directory automatically (copyright, changelog); explicitly globbing the whole usr/share/doc tree is redundant and can pull in unintended files.
Minor/notes (not blockers): nestopia-jg (control:33) declares no ${misc:Depends}/${shlibs:Depends} for its .so plugin; the copyright file lists "2018 Phil Smith" who isn't in the upstream LICENSES/README copyright notices.
Bottom line: The core Nestopia (GPL-2.0+) and nes_ntsc (LGPL-2.1+) licensing is correctly and DFSG-compatibly declared. The main licensing gap is the statically-linked QTea frontend not being reflected in debian/copyright, and the unverified test.bmp/jg_compat.h provenance. On packaging, the stale upstream/metadata + homepage and the fragile mkdir build are the clearest quality issues.
Hope that's useful :-)
Thanks!
Further information may be found at:
https://dfsg-new-queue.debian.org/reviews/nestopia
Regards, Andrew McMillan
Member of the DFSG, Licensing & New Packages Team
===
Please feel free to respond to this email if you don't understand why
your files were rejected, or if you upload new files which address our
concerns.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-games-devel/attachments/20260928/6e0191c1/attachment.sig>
More information about the Pkg-games-devel
mailing list