[Pkg-privacy-maintainers] txtorcon is marked for autoremoval from testing
meejah
meejah at meejah.ca
Tue May 26 18:01:26 BST 2026
Yes, removing geo-ip as a dependency is fine.
There have been other issues with this in the past, and as you point out it's optional anyway.
Would it help if I made an upstream release without this functionality?
On Sun, 24 May 2026, at 12:47, Sascha Steinbiss wrote:
> Dear list, hi meejah,
>
> I am the maintainer of gnome-keysign, who, via its dependency magic-
> wormhole, is affected by the issue below:
>
>> txtorcon 24.8.0-1.1 is marked for autoremoval from testing on
>> 2026-05-31
>>
>> It (build-)depends on packages with these RC bugs: 1134158: geoip-
>> database: license of package doesn't match license provided upstream
>> and is likely not DFSG-compliant https:// bugs.debian.org/1134158
>
> Would it be acceptable to just remove the optional dependency on
> python3-geoip (and hence geoip-database) from the Debian txtorcon
> package? It seems to only be required by upstream when the [dev] option
> is passed on installation [1,2].
>
> I just tested removing the python3-geoip deps and rebuilding txtorcon's
> reverse dependencies in Debian using ratt [3] and all 4 such packages at
> least _built_ correctly (except tahoe-lafs, whose builds currently fail
> for other reasons [4]).
> Also see attached patch.
>
> I know this does not solve the underlying fundamental license issue with
> geoip-database we have in Debian but at least remove some urgency based
> on removals affecting other packages.
>
> What do you think? Any other ideas to address the situation?
>
> CC'ing the txtorcon and magic-wormhole upstream (meejah) for potentially
> more insight on whether the geoip dependency is actually required.
>
> Thanks and best regards
> Sascha
>
>
> [1] https://github.com/meejah/txtorcon/
> blob/85c213092104aebea24adc858ab0ffdd0791ad1d/setup.py#L46
> [2] https://github.com/meejah/txtorcon/
> blob/85c213092104aebea24adc858ab0ffdd0791ad1d/dev-requirements.txt#L14
> [3] https://github.com/debian/ratt
> [4] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1123360
> Attachments:
> * txtorcon-remove-geoip.diff
> * OpenPGP_signature.asc
More information about the Pkg-privacy-maintainers
mailing list